Exploit for CVE-2025-30406
CVE-2025-30406 Exploit for CVE-2025-30406
Gladinet CentreStack Remote Code Execution via Deserialization Vulnerability
Gladinet CentreStack, up to version 16.1.10296.56315, has a serious deserialization vulnerability in its portal. The issue stems from a hardcoded machineKey that allows threat actors to create a specialized payload for server-side deserialization. If an attacker knows the machineKey, they can potentially execute remote code. This vulnerability was actively exploited in the wild during March 2025. The problem was fixed in version 16.4.10315.56368. A CentreStack administrator can manually mitigate the risk by deleting the machineKey located in the portal\web.config file.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
gladinet centrestack |
CentreStack RCE exploited as zero-day to breach file sharing servers By Bill Toulas April 9, 2025 11:38 AM 0 Hackers exploited a vulnerability in Gladinet CentreStack's secure file-sharing software as a zero-day since March to breach storage servers Gladinet CentreStack is an enterprise file-sharing and access platform that turns on-premise file servers (like Windows servers with SMB shares) into secure, cloud-like file systems supporting remote access to internal file shares, file syncing and s...