Gladinet Flaw: Hard-Coded Keys Enable Remote Code Execution Exploit

Critical Vulnerability in Gladinet CentreStack and Triofox Enables Unauthorized Access and Remote Code Execution Through Hard-Coded Cryptographic Keys

  • A vulnerability involving hard-coded cryptographic keys impacts Gladinet CentreStack and Triofox products.
  • Threat actors exploit the flaw to access sensitive files like web.config and perform remote code execution through ViewState deserialization.
  • The flaw relates to the static key generation by the “GenerateSecKey()” function in GladCtrl64.dll.
  • At least nine organizations across multiple sectors have been affected as of December 10, 2025.
  • Users are advised to update to the latest software version and rotate machine keys to mitigate the risk.

A new vulnerability affecting Gladinet CentreStack and Triofox software has been actively exploited, impacting at least nine organizations as of December 10, 2025. The flaw stems from hard-coded cryptographic keys embedded in the products, which allow attackers to access critical configuration files and execute remote code.

- Advertisement -

Security researcher Bryan Masters explained that threat actors can leverage this weakness to access the web.config file, enabling deserialization attacks through ViewState and leading to remote code execution. The problem originates from a function named “GenerateSecKey()” within the “GladCtrl64.dll” library. This function produces fixed 100-byte strings used to derive cryptographic keys, which remain unchanged over time.

Because these keys never change, attackers can decrypt or forge access tickets containing authorization data such as usernames and passwords. This grants unauthorized access to files and the ability to craft tickets that never expire by manipulating the timestamp field. The attacks typically target the “/storage/filesvr.dn” endpoint using specially crafted URL requests.

The intrusions leave username and password fields blank, causing the system to default to the IIS Application Pool Identity, which broadens unauthorized access. The reused tickets allow persistent access to sensitive data, including the machine key needed for ViewState deserialization exploits.

Affected organizations span healthcare, technology, and other sectors, with attacks traced to the IP address 147.124.216[.]205. The threat actors combine this vulnerability with a previously disclosed flaw (CVE-2025-11371) to access the machine key from the web.config file. According to Huntress, attackers performed deserialization attacks but encountered failures in retrieving execution output.

- Advertisement -

To address the issue, users of CentreStack and Triofox are urged to update their software to version 16.12.10420.56791, released on December 8, 2025, as indicated on the official CentreStack and Triofox release pages. Monitoring logs for the encrypted string “vghpI7EToZUDIZDdprSubL3mTZ2” is recommended to detect indicators of compromise.

If signs of exploitation are found, administrators should rotate machine keys following guidelines outlined here. The process involves backing up the web.config file, generating new machine keys in IIS Manager under the ASP.NET section, and restarting IIS on all worker nodes.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Silver’s rally reignites debate: Bitcoin vs. precious metals

Silver reached a record spot price near $94 per ounce on Monday.Gold climbed to...

Satoshi-era 909 BTC wallet wakes after 13 years, moves $85M.

A Satoshi‑era wallet transferred its full balance of 909.38 BTC—about $84.6 million—after 13 years...

Cardano Volatility Fuels Comeback Hopes After Hoskinson Buzz

Cardano (ADA) trades at $0.36, up 2% in the last 24 hours, after sharp...

Ethereum Leads Bitcoin Liquidations as Macro Headwinds Bite.

Ethereum led crypto liquidations over the last 24 hours, surpassing Bitcoin.Total crypto liquidations totaled...

Bitcoin Falls Amid US-EU Tariff Fears, Drops Near $92K today

Bitcoin traded near $92,000 on Jan. 19 after a weekend decline tied to concerns...
- Advertisement -

Must Read

Top Best Metaverse Worlds To Buy Land

The metaverse has grown in our everyday conversation since Facebook announced its rebranding in October 2021 to META. The metaverse is a virtual world,...
Bitcoin (BTC) $ 90,783.00 2.57%
Ethereum (ETH) $ 3,091.26 3.75%
XRP (XRP) $ 1.92 2.66%
Bittensor (TAO) $ 239.83 4.41%
Polkadot (DOT) $ 1.98 0.82%
Cardano (ADA) $ 0.358822 2.35%
Chainlink (LINK) $ 12.50 2.49%
Hyperliquid (HYPE) $ 23.01 4.57%
Monero (XMR) $ 584.27 7.85%
Hedera (HBAR) $ 0.107071 2.82%
Toncoin (TON) $ 1.56 3.90%