CVE-2025-30406
Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability
9.8
CVSS 3.1
94.3 %
EPSS (current)
2025-04-08
KEV addition
No
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: Gladinet / CentreStack
Published: 2025-04-03 · Due (CISA): 2025-04-29
CWE: CWE-798 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| nuclei | http/cves/2025/CVE-2025-30406.yaml | Gladinet CentreStack < 16.4.10315.56368 Use of Hard-coded Key Leads to Unauthenticated RCE | – |
| metasploit | exploit/windows/http/gladinet_viewstate_deserialization_cve_2025_30406 | exploit/windows/http/gladinet_viewstate_deserialization_cve_2025_30406 | 2025-04-03 |
References only — no downloads or instructions.