CVE-2025-11371

Source
https://cve.org/CVERecord?id=CVE-2025-11371
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-11371.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-11371
Published
2025-10-09T17:15:58.507Z
Modified
2026-03-12T17:34:00.417049Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild. 

This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-11371.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "16.10.10408.56683"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "16.7.10368.56560"
            }
        ]
    }
]