Fixing and finding

[Jump to remediation plan](#remediation)

CVE ID

# CVE-2025-12480

Published 2025-11-10

Updated 3 months ago

Vendor/s

Gladinet

Product/s

Triofox

Version/s

\* > 16.7.10368.56560

KEV Status

Active Exploitation

Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.

CVSS Score (v3.1)

9.1

/ 10

Critical

Severity Details

Base score

9.1 Critical

Attack vector

Network

Attack complexity

Low

Privileges required

None

User interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

None

Table of Contents

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

## Description

CVE-2025-12480 is a critical access control vulnerability in Gladinet Triofox (CVSS 9.1) that allows attackers to access setup pages. Patch immediately.

## Why this matters

CVE-2025-12480 is a critical access control vulnerability in Gladinet Triofox with a CVSS score of 9.1. It allows unauthenticated remote attackers to access initial configuration pages even after the system is fully deployed. This flaw is particularly dangerous because it is actively exploited in the wild and listed on CISA’s Known Exploited Vulnerabilities (KEV) catalog. Security teams must act quickly, as exploitation can lead to unauthorized reconfiguration of the file-sharing environment, potentially resulting in complete data exposure or system takeover.

## CPE

Gladinet

| Product | Version Start | Version End (excl.) | Status     |
| ------- | ------------- | ------------------- | ---------- |
| triofox | \*            | 16.7.10368.56560    | vulnerable |

## Related weakness (CWE)

CWE-284

## Remediation plan

1

### Apply official patches

Download and apply the latest security updates from Gladinet to resolve the improper access control flaw in the Triofox platform.

2

### Update affected systems

Upgrade all Triofox deployments to version 16.7.10368.56560 or later, as all previous versions are susceptible to this vulnerability.

3

### Restrict access

Use firewalls or access control lists (ACLs) to ensure that administrative and setup interfaces are only accessible from internal, authorized management networks.

4

### Monitor for exploitation

Audit web server logs for unexpected traffic to setup-related directories and monitor for unauthorized changes to system configuration settings.

## Detection Guidance

Detecting exploitation of CVE-2025-12480 involves monitoring web server logs for inbound requests to setup or installation URIs (such as /setup or /install) from external sources. Look for successful HTTP 200 status codes on these paths post-deployment. Additionally, security teams should use network scanning tools to verify if sensitive configuration pages are exposed to the public internet.

## References

[https://access.triofox.com/releases\_history/ Release Notes ](https://access.triofox.com/releases_history/)[https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480 Exploit Third Party Advisory ](https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480)[https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2025/MNDT-2025-0008.md Third Party Advisory ](https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2025/MNDT-2025-0008.md)[https://www.triofox.com/ Product ](https://www.triofox.com/)[https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field\_cve=CVE-2025-12480 US Government Resource](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-12480)

## Sources

NIST National Vulnerability Database (NVD)

CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](https://www.upguard.com/contact-sales)

[Free trial](https://www.upguard.com/demo)
