VYPR

Triofox

by Gladinet

CVEs (3)

  • CVE-2025-14611CriKEVDec 12, 2025
    risk 0.83cvss 9.8epss 0.53

    Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a…

  • CVE-2025-12480CriKEVNov 10, 2025
    risk 0.78cvss 9.1epss 0.95

    Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.

  • CVE-2025-11371HigKEVOct 9, 2025
    risk 0.71cvss 7.5epss 0.92

    In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.  This issue impacts…