module
Gladinet CentreStack/Triofox Path Traversal
| Disclosed | Created |
|---|---|
| Apr 3, 2025 | Feb 4, 2026 |
Disclosed
Apr 3, 2025
Created
Feb 4, 2026
Description
This module exploits a path traversal vulnerability (CVE-2025-11371) in
Gladinet CentreStack and Triofox that allows an unauthenticated attacker to read
arbitrary files from the server's file system.
The vulnerability exists in the `/storage/t.dn` endpoint which does not properly
sanitize the `s` parameter, allowing path traversal attacks. This can be used
to read sensitive files such as Web.config which contains the machineKey used for
ViewState deserialization attacks (CVE-2025-30406).
Gladinet CentreStack versions up to 16.10.10408.56683 are vulnerable.
Gladinet Triofox versions up to 16.10.10408.56683 are vulnerable.
Gladinet CentreStack and Triofox that allows an unauthenticated attacker to read
arbitrary files from the server's file system.
The vulnerability exists in the `/storage/t.dn` endpoint which does not properly
sanitize the `s` parameter, allowing path traversal attacks. This can be used
to read sensitive files such as Web.config which contains the machineKey used for
ViewState deserialization attacks (CVE-2025-30406).
Gladinet CentreStack versions up to 16.10.10408.56683 are vulnerable.
Gladinet Triofox versions up to 16.10.10408.56683 are vulnerable.
Authors
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.