Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

A Critical Zero-Day Exploit in Gladinet Triofox: Understanding the Risks and Mitigations



A critical zero-day exploit has been discovered in Gladinet Triofox, leaving its affected instances vulnerable to remote code execution attacks due to hardcoded cryptographic keys. Seven unique organizations have been compromised so far, highlighting the importance of staying vigilant and proactive in addressing emerging security threats. Update your software immediately to safeguard against potential risks.

  • A critical zero-day exploit (CVE-2025-30406) has been discovered in the Gladinet Triofox remote access solution.
  • The vulnerability allows for remote code execution due to hardcoded cryptographic keys.
  • Seven unique organizations have been compromised so far, according to Huntress.
  • The software affects versions up to 16.4.10317.56372, and the CentreStack software is installed on approximately 120 endpoints.
  • Attackers use PowerShell scripts to download and sideload a DLL, conduct lateral movement, and install MeshCentral for remote access.
  • Users are advised to update their instances to the latest version to safeguard against potential risks.



  • In recent days, a critical zero-day exploit has been discovered in the Gladinet Triofox remote access and collaboration solution. This vulnerability, designated as CVE-2025-30406 with a CVSS score of 9.0, leaves its affected instances vulnerable to remote code execution attacks due to the use of hardcoded cryptographic keys in their configuration files. Huntress, a cybersecurity firm, has been tracking this exploit since March 2025 and has recently disclosed that seven unique organizations have been compromised to date.

    The vulnerability was discovered as part of CentreStack version 16.4.10315.56368 release on April 3, 2025, but it also affects the Gladinet Triofox software up to version 16.4.10317.56372. According to John Hammond, principal cybersecurity researcher at Huntress, "By default, previous versions of the Triofox software have the same hardcoded cryptographic keys in their configuration file, and can be easily abused for remote code execution."

    The CentreStack software is installed on approximately 120 endpoints, as revealed through telemetry data gathered from its partner base. Furthermore, the attackers have been observed using an encoded PowerShell script to download and sideload a DLL, followed by conducting lateral movement and installing MeshCentral for remote access.

    Huntress noted that the attackers are identified as running Impacket PowerShell commands to perform various enumeration commands and install MeshAgent. The scale of these campaigns is currently unknown, nor is it clear what their end goal is. However, in light of active exploitation, it's essential that users update their instances to the latest version to safeguard against potential risks.

    The attack vector employed by the attackers mirrors recent attacks utilizing the CrushFTP vulnerability, highlighting the importance of staying vigilant and proactive in addressing these emerging security threats.

    In conclusion, this critical zero-day exploit serves as a stark reminder of the importance of keeping software up-to-date and the need for organizations to implement robust cybersecurity measures to protect against such exploits. By taking immediate action and adhering to recommended mitigation strategies, organizations can significantly reduce their risk exposure to potential attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/A-Critical-Zero-Day-Exploit-in-Gladinet-Triofox-Understanding-the-Risks-and-Mitigations-ehn.shtml

  • Published: Tue Apr 15 00:34:51 2025 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us