H-ISAC TLP White: Vulnerability Bulletin: Active Exploitation of Gladinet CentreStack and TrioFox Products (CVE-2025-11371)

On October 9, 2025, Huntress disclosed the observance of active, in-the-wild exploitation of CVE-2025-11371, an unauthenticated local file inclusion (LFI) vulnerability impacting Gladinet CentreStack and TrioFox products. The cybersecurity company has confirmed that three of its customers have been affected so far.

This flaw is currently a zero-day with no official vendor patch, but a strong mitigation is available that organizations should implement immediately. Exploiting this vulnerability allows attackers to retrieve configuration keys, which they then use to achieve remote code execution (RCE) and compromise the server.

Health-ISAC is sharing this to increase situational awareness and encourage organizations to assess their level of risk to the vulnerability and exploitation activity.

View the detailed report below.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272