← Back

Triofox

triofox

Vendor: Gladinet • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gladinet
2Centrestack
Triofox
Dec 16, 2025
Dec 12, 2025
7.1 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and...Show more
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.Show less
1Gladinet
1Triofox
Nov 14, 2025
Nov 10, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
1Gladinet
2Centrestack
Triofox
Nov 5, 2025
Oct 9, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerabili...Show more
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.  This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560Show less