« Volver al listado

Gladinet

Gladinet Centrestack: vulnerabilidades y CVE

Gladinet Centrestack tiene 13 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 4 son críticas y 3 figuran en el catálogo de explotación activa de CISA.

CVE13
Últimos 12 meses8
Críticas4
Explotadas activamente3

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-14611Alta (7.1)53%⚠ Explotación activa12 dic 2025
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and…
CVE-2025-11371Alta (7.5)92%⚠ Explotación activa9 oct 2025
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this…
CVE-2025-30406Crítica (9.8)94%⚠ Explotación activa3 abr 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-54368Alta (8.7)0.71%—30 jul 2026
CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted x-glad-filter…
CVE-2026-54367Alta (8.8)0.32%—30 jul 2026
CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack…
CVE-2026-54366Alta (8.7)0.49%—30 jul 2026
CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to the SharePoint storage…
CVE-2026-54365Alta (8.7)0.37%—30 jul 2026
CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded…
CVE-2026-54364Media (6.9)0.43%—30 jul 2026
CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inject arbitrary session variables by embedding newline and tab characters into a crafted AccountName…
CVE-2026-54363Crítica (9.3)0.69%—30 jul 2026
CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for…
CVE-2025-14611Alta (7.1)53%⚠ Explotación activa12 dic 2025
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and…
CVE-2025-11371Alta (7.5)92%⚠ Explotación activa9 oct 2025
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this…
CVE-2025-30406Crítica (9.8)94%⚠ Explotación activa3 abr 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This…
CVE-2024-37783Media (5.4)0.38%—22 nov 2024
A reflected cross-site scripting (XSS) vulnerability in Gladinet CentreStack v13.12.9934.54690 allows attackers to inject malicious JavaScript into the web browser of a victim via the sessionId parameter at…
CVE-2024-37782Crítica (9.8)1.0%—22 nov 2024
An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field.
CVE-2023-26830Alta (7.2)1.1%—31 mar 2023
An unrestricted file upload vulnerability in the administrative portal branding component of Gladinet CentreStack before 13.5.9808 allows authenticated attackers to execute arbitrary code by uploading malicious files to…
CVE-2023-26829Crítica (9.8)1.2%—31 mar 2023
An authentication bypass vulnerability in the Password Reset component of Gladinet CentreStack before 13.5.9808 allows remote attackers to set a new password for any valid user account, without needing the previous…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application8
  2. T1005 Data from Local System2
  3. T1059 Command and Scripting Interpreter2
  4. T1059.001 PowerShell1
  5. T1078 Valid Accounts1
  6. T1078.001 Default Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Gladinet