BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Gladinet Flaw: Hard-Coded Keys Enable Remote Code Execution Exploit

Critical Vulnerability in Gladinet CentreStack and Triofox Enables Unauthorized Access and Remote Code Execution Through Hard-Coded Cryptographic Keys

  • A vulnerability involving hard-coded cryptographic keys impacts Gladinet CentreStack and Triofox products.
  • Threat actors exploit the flaw to access sensitive files like web.config and perform remote code execution through ViewState deserialization.
  • The flaw relates to the static key generation by the “GenerateSecKey()” function in GladCtrl64.dll.
  • At least nine organizations across multiple sectors have been affected as of December 10, 2025.
  • Users are advised to update to the latest software version and rotate machine keys to mitigate the risk.

A new vulnerability affecting Gladinet CentreStack and Triofox software has been actively exploited, impacting at least nine organizations as of December 10, 2025. The flaw stems from hard-coded cryptographic keys embedded in the products, which allow attackers to access critical configuration files and execute remote code.

- Advertisement -

Security researcher Bryan Masters explained that threat actors can leverage this weakness to access the web.config file, enabling deserialization attacks through ViewState and leading to remote code execution. The problem originates from a function named “GenerateSecKey()” within the “GladCtrl64.dll” library. This function produces fixed 100-byte strings used to derive cryptographic keys, which remain unchanged over time.

Because these keys never change, attackers can decrypt or forge access tickets containing authorization data such as usernames and passwords. This grants unauthorized access to files and the ability to craft tickets that never expire by manipulating the timestamp field. The attacks typically target the “/storage/filesvr.dn” endpoint using specially crafted URL requests.

The intrusions leave username and password fields blank, causing the system to default to the IIS Application Pool Identity, which broadens unauthorized access. The reused tickets allow persistent access to sensitive data, including the machine key needed for ViewState deserialization exploits.

Affected organizations span healthcare, technology, and other sectors, with attacks traced to the IP address 147.124.216[.]205. The threat actors combine this vulnerability with a previously disclosed flaw (CVE-2025-11371) to access the machine key from the web.config file. According to Huntress, attackers performed deserialization attacks but encountered failures in retrieving execution output.

- Advertisement -

To address the issue, users of CentreStack and Triofox are urged to update their software to version 16.12.10420.56791, released on December 8, 2025, as indicated on the official CentreStack and Triofox release pages. Monitoring logs for the encrypted string “vghpI7EToZUDIZDdprSubL3mTZ2” is recommended to detect indicators of compromise.

If signs of exploitation are found, administrators should rotate machine keys following guidelines outlined here. The process involves backing up the web.config file, generating new machine keys in IIS Manager under the ASP.NET section, and restarting IIS on all worker nodes.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

U.S. Blocks Anthropic’s Top AI Models Over Security Fears

The U.S. government ordered Anthropic to suspend foreign access to its advanced AI models,...

Critical Splunk Vulnerability Allows Unauthenticated RCE

Splunk has patched a critical vulnerability, CVE-2026-20253, rated 9.8 on the CVSS scale, allowing...

AI Agent Bills Operator $6.5k After Wild AWS Spree

An AI agent deployed by an operator named JertLinc autonomously spun up five powerful...

Bitcoin ETF Inflows Spark Hope After 2026 Price Lows

Bitcoin has plunged to 2026 lows of under $60,000, down 50% from its October...

Investors Bet on Onchain Credit Infrastructure Over DeFi

Morpho Labs raises $175M from investors like Paradigm, aiming to become a foundational credit...

Must Read

The 13 Best Crypto Advertising Networks to Grow Your Project

TABLE OF CONTENTSWhy Traditional Ad Networks (Like Google & Facebook) Fail CryptoQuick-View Comparison TableHow to Choose the Right Crypto Ad Network for Your ProjectBest...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading