CVE-2025-30406Active Exploitation(gladinet / centrestack)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for gladinet centrestack systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to achieve remote code execution. NOTE: a CentreStack admin can manually delete the machineKey defined in portal\web.config.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-04-29. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-321CWE-798

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • centrestack

Threat summary

  • Active exploitation appears in 4 classified signals
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 4 signals
  • Technical details provided in 3 signals
  • Peaked 3d ago at 1 mentions (2026-02-17); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
centrestack

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-17: 1Mentions · 2026-04-17: 1Mentions · 2026-05-13: 1Mentions · 2026-08-14: 1Active Exploitation · 2026-02-17: 1Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-05-13: 1Active Exploitation · 2026-08-14: 1Technical Details · 2026-04-17: 1Technical Details · 2026-05-13: 1Technical Details · 2026-08-14: 102-1704-1705-1308-14
Signal classification1 categories
Active Exploitation
4100.0%
Referenced assets7 URLs
Full discourse4 posts
  • Jamie Levy🦉@gleeda
    Active Exploitation

    Do you have mad skills 🥷and want to join the Adversary Tactics team at @HuntressLabs ? We're looking for that special someone to help lead our Rapid Response engagements. Some examples of deliverables are: * SolarWinds Web Help Desk: https://www.huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399 * React2Shell: https://www.huntress.com/blog/peerblight-linux-backdoor-exploits-react2shell * Gladinet / Triofox: https://www.huntress.com/blog/cve-2025-30406-critical-gladinet-centrestack-triofox-vulnerability-exploited-in-the-wild * CrushFTP: https://www.huntress.com/blog/crushftp-cve-2025-31161-auth-bypass-and-post-exploitation

    Post summary

    The post references recent CVEs that have been actively exploited in the wild, highlighting the need for rapid-response expertise.

    0231732317.7K
    9.8K followersView on X
  • The DFIR Report@TheDFIRReport
    Active Exploitation

    🔒 Private DFIR Report: ViewState of Mind, Gladinet Exploit Opens the Door In January, a threat actor gained initial access by exploiting CVE-2025-30406 on an exposed Gladinet CentreStack server, large VIEWSTATE payloads in the network traffic gave the exploitation away. Request access or a demo 👉 https://buff.ly/5OJGkqu #DFIR #ThreatIntel

    Post summary

    A private DFIR report confirms CVE-2025-30406 was actively exploited in January on an exposed Gladinet CentreStack server, with large ViewState payloads enabling initial access.

    06024163.9K
    70.2K followersView on X
  • The DFIR Report@TheDFIRReport
    Active Exploitation

    🔒 Private DFIR Report: ViewState of Mind: Gladinet Exploit Opens the Door In January, we observed a threat actor gain initial access to an environment by exploiting CVE-2025-30406 on an exposed Gladinet CentreStack server. Looking at the network traffic at the time of this connection showed large VIEWSTATE payloads being sent to the server. Based on this pattern in the network traffic, the command execution from the IIS server, and the version of Gladinet CentreStack, we assessed that the threat actor successfully exploited CVE-2025-30406 for initial access in this intrusion. Private report — request access or a demo: https://thedfirreport.com/products/threat-intel/private-dfir-reports/

    Post summary

    The report records that CVE‑2025‑30406 was actively exploited in a real‑world incident via large VIEWSTATE payloads on a Gladinet CentreStack server, confirming active use in the wild.

    01002885.5K
    68.0K followersView on X
  • デジセキュア@dejital_secure
    Active Exploitation

    HuntressがGladinet CentreStack/Triofoxの重大脆弱性(CVE-2025-30406, CVSS 9.0)の実環境悪用を報告。7組織・約120端末に影響。デフォルト暗号鍵がRCEの原因。 https://www.securityweek.com/huntress-documents-in-the-wild-exploitation-of-critical-gladinet-vulnerabilities/ #Vulnerability

    Post summary

    Huntress reports real‑world exploitation of Gladinet CentreStack/Triofox CVE‑2025‑30406 affecting seven organizations (~120 endpoints) via a default encryption key that enables RCE, with no patch or workaround mentioned.

    00000544
    10 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgladinetcentrestack---

Explore more