PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-11371 Gladinet CVE debrief

CVE-2025-11371 is a Gladinet CentreStack and Triofox vulnerability listed by CISA in the Known Exploited Vulnerabilities catalog. The recorded issue is described as files or directories being accessible to external parties, which indicates an unauthorized exposure risk rather than a software crash or performance problem. Because CISA has marked it as known exploited, organizations should treat it as an urgent defensive priority and follow the vendor and CISA guidance in the official records.

Vendor
Gladinet
Product
CentreStack and Triofox
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2025-11-04
Original CVE updated
2025-11-04
Advisory published
2025-11-04
Advisory updated
2025-11-04

Who should care

Organizations running Gladinet CentreStack or Triofox, especially security teams, system administrators, and cloud-service owners responsible for access controls and externally reachable file-sharing deployments.

Technical summary

The supplied source corpus identifies CVE-2025-11371 as a Gladinet CentreStack and Triofox 'Files or Directories Accessible to External Parties Vulnerability.' CISA added the issue to the KEV catalog on 2025-11-04, indicating known exploitation. The corpus does not include deeper vendor advisory text, exploit conditions, or a CVSS score, so the most defensible technical summary is that inadequate access control can expose files or directories beyond intended users.

Defensive priority

High

Recommended defensive actions

  • Apply mitigations per the vendor instructions referenced by CISA.
  • Follow applicable CISA BOD 22-01 guidance for cloud services if your deployment is cloud-hosted or service-based.
  • If mitigations are unavailable, discontinue use of the affected product or isolate the deployment until remediation is possible.
  • Validate that file and directory access controls, sharing permissions, and authentication boundaries are correctly enforced on exposed instances.
  • Review logs and access records for unexpected external access to sensitive files or directories.

Evidence notes

CISA's KEV record for CVE-2025-11371 names Gladinet CentreStack and Triofox and describes the issue as 'Files or Directories Accessible to External Parties Vulnerability.' The KEV entry was added on 2025-11-04 with a due date of 2025-11-25 and instructs defenders to apply vendor mitigations, follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. The supplied corpus also includes official CVE and NVD links, but no additional technical detail or CVSS score.

Official resources

Publicly listed in the supplied records on 2025-11-04; CISA added CVE-2025-11371 to the KEV catalog the same day.