VendorsGladinetcentrestackall versions
Vulnerabilities

Gladinet Centrestack

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2025-30406
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to achieve remote code execution. NOTE: a CentreStack admin can manually delete the machineKey defined in portal\web.config.
Published 2025-04-03 · Analyzed
9.8KEVEPSS 0.943
CVE-2025-14611
Gladinet CentreStack and TrioFox Hard Coded AES Keys
Published 2025-12-12 · Analyzed
9.8KEVEPSS 0.533
CVE-2023-26829
An authentication bypass vulnerability in the Password Reset component of Gladinet CentreStack before 13.5.9808 allows remote attackers to set a new password for any valid user account, without needing the previous known password, resulting in a full authentication bypass.
Published 2023-03-31 · Modified
9.8EPSS 0.012
CVE-2025-11371
Gladinet CentreStack and TrioFox Local File Inclusion Flaw
Published 2025-10-09 · Analyzed
7.5KEVEPSS 0.921
CVE-2023-26830
An unrestricted file upload vulnerability in the administrative portal branding component of Gladinet CentreStack before 13.5.9808 allows authenticated attackers to execute arbitrary code by uploading malicious files to the server.
Published 2023-03-31 · Modified
7.2EPSS 0.011