CVE-2025-14611
Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 7.1
- EPSS
- 50.9% 백분위 98.8% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2026.01.05
- 공개일
- 2025.12.13
CISA KEV에 등록된 실제 악용 확인 취약점
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.
공급사 Gladinet
제품 CentreStack and Triofox
영향 버전 0, < 16.12.10420.56791
수정 버전 16.12.10420.56791
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
조치 기한: 2026.01.05CVSS 벡터 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE CWE-798
KEV 등록일 2025.12.15
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://www.centrestack.com/p/gce_latest_release.html ; https://access.triofox.com/releases_history/; https://support.centrestack.com/hc/en-us/articles/360007159054-Hardening-the-CentreStack-Cluster#h_01JQRV57T37HJFQZKBZH9NBXQP ; https://nvd.nist.gov/vuln/detail/CVE-2025-14611
EPSS 데이터 기준일 2026.06.27