As cited
Copy frozen at (site build).
vulnerabilities
Gladinet CentreStack/Triofox: Cryptography Vulnerability | Huntress
Gladinet's CentreStack and Triofox products contain hardcoded cryptographic keys in their AES implementation, creating a vulnerability that threat actors are actively exploiting. The flaw allows attackers to potentially decrypt sensitive data protected by the affected encryption mechanism. This issue affects organizations relying on these file sharing and synchronization solutions for data protection.
Why it matters: Organizations using CentreStack or Triofox face immediate risk of data compromise if the hardcoded keys are leveraged to decrypt stored or transmitted data; patching or migrating away from vulnerable versions should be prioritized.
- Source published
- First seen by Cybersecurity Tracker