Detects Gladinet CentreStack and Triofox instances prior to version 16.12.10420.56791 where the hardcoded AES-256-CBC key from GladCtrl64.dll allows unauthenticated attackers to forge encrypted access tickets and download arbitrary files via the /storage/filesvr.dn endpoint. This can be chained with CVE-2025-30406 for full remote code execution.
Is your app exploitable through CVE-2025-14611?
Scan your domain free