All verified exploits

CVE-2025-14611 Hardcoded AES Key Arbitrary File Read

Deterministic high CentreStack CISA KEV Added cve-verified-cve-2025-14611

Detects Gladinet CentreStack and Triofox instances prior to version 16.12.10420.56791 where the hardcoded AES-256-CBC key from GladCtrl64.dll allows unauthenticated attackers to forge encrypted access tickets and download arbitrary files via the /storage/filesvr.dn endpoint. This can be chained with CVE-2025-30406 for full remote code execution.

Is your app exploitable through CVE-2025-14611?

Scan your domain free