Gladinet Centrestack Local File Inclusion

Strike ID:
E25-kirv1
CVSS:
7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
False Positive:
f
Variants:
1
Year:
2025

Description

This strike exploits a local file inclusion vulnerability in Gladinet CentreStack and TrioFox. The vulnerability is due to improper validation of user-supplied file paths in the /storage/t.dn endpoint, allowing traversal sequences that expose arbitrary files such as Web.config. An unauthenticated remote attacker can retrieve sensitive configuration files, potentially exposing secrets and enabling further compromise, including remote code execution through chained attacks.

CVE

References