Executive Summary
In November 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added critical vulnerabilities impacting Gladinet and Control Web Panel (CWP) to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in the wild. Attackers have leveraged CVE-2025-11371 and similar flaws, which expose sensitive files or directories, enabling unauthorized code execution and unauthorized access to critical business data. Exploitation techniques include remote access and privilege escalation, with incidents observed in both enterprise and cloud environments. The exploited weaknesses have led to compromised systems and elevated business risk for affected organizations.
This incident highlights an escalating trend in the exploitation of web-facing management panels and software supply chain components, making east-west traffic security and timely vulnerability management crucial for defenders. Regulatory and industry pressure is mounting as the pace and sophistication of attacks accelerate.
Why This Matters Now
Rapid weaponization of new vulnerabilities means organizations cannot afford delays in patching or in deploying robust segmentation, detection, and cloud controls. The ongoing exploitation of Gladinet and CWP flaws underscores the urgency for real-time visibility and automated policy enforcement to mitigate modern attack surface risks.
Attack Path Analysis
Attackers exploited publicly accessible vulnerabilities in Gladinet and CWP systems to gain unauthorized access. After initial compromise, they sought to escalate privileges, potentially abusing weak configurations or credentials. The attackers then moved laterally within the cloud or hybrid environment, targeting adjacent workloads and sensitive data. Command and control channels were established to communicate with external infrastructure, often blending with normal outbound traffic. Data was exfiltrated through covert or encrypted channels, evading detection using common communication ports. Finally, the attackers aimed to disrupt operations, deploy ransomware, or achieve other destructive outcomes.
Kill Chain Progression
Initial Compromise
Description
Adversaries leveraged CVE-2025-11371 and related flaws in exposed Gladinet and CWP services to gain unauthorized initial access to the environment.
Related CVEs
CVE-2025-11371
CVSS 7.5An unauthenticated Local File Inclusion vulnerability in Gladinet CentreStack and TrioFox allows unintended disclosure of system files.
Affected Products:
Gladinet CentreStack – <= 16.7.10368.56560
Gladinet TrioFox – <= 16.7.10368.56560
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
External Remote Services
Network Service Discovery
Command and Scripting Interpreter
Valid Accounts
Impair Defenses
Remote Services
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Public-Facing Application Security
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Continuous Vulnerability Management
Control ID: Asset Management - Vulnerability Management
NIS2 Directive – Security of Network and Information Systems
Control ID: Article 21(2), (d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Critical vulnerability exploitation in Gladinet and Control Web Panel threatens IT infrastructure requiring immediate patching and enhanced segmentation controls.
Government Administration
CISA KEV addition indicates active exploitation targeting government systems necessitating urgent vulnerability management and zero trust implementation.
Financial Services
File access vulnerabilities pose data exfiltration risks to financial institutions requiring enhanced egress filtering and anomaly detection capabilities.
Health Care / Life Sciences
Directory access flaws threaten HIPAA compliance in healthcare systems demanding immediate multicloud visibility and encrypted traffic protection measures.
Sources
- CISA Adds Gladinet and CWP Flaws to KEV Catalog Amid Active Exploitation Evidencehttps://thehackernews.com/2025/11/cisa-adds-gladinet-and-cwp-flaws-to-kev.htmlVerified
- CVE-2025-11371 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-11371Verified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-11371Verified
- Gladinet CentreStack and TrioFox Local File Inclusion Flawhttps://www.huntress.com/blog/gladinet-centrestack-triofox-local-file-inclusion-flawVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust segmentation, advanced east-west controls, egress policy enforcement, and inline threat detection would have limited the adversary's ability to exploit vulnerabilities, move laterally, establish C2, and exfiltrate data, greatly reducing impact at each kill chain stage.
Control: Cloud Firewall (ACF)
Mitigation: Prevents unauthorized exposure and exploitation of vulnerable services.
Control: Zero Trust Segmentation
Mitigation: Limits unauthorized privilege escalation by restricting access between workloads and management surfaces.
Control: East-West Traffic Security
Mitigation: Detects and blocks unauthorized internal movement between cloud workloads.
Control: Inline IPS (Suricata)
Mitigation: Blocks known malicious C2 patterns and signatures.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents unauthorized data transfer outside the organization.
Detects destructive or anomalous actions in real time.
Impact at a Glance
Affected Business Functions
- File Sharing
- Remote Access
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive system files, including configuration files and credentials, leading to unauthorized access and data breaches.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce strict firewalling and cloud-native segmentation to eliminate exposed attack surfaces.
- • Implement real-time east-west inspection to block lateral movement and internal pivoting.
- • Apply granular egress controls to restrict and monitor all outbound data flows.
- • Deploy inline threat detection and anomaly response for rapid containment of emerging threats.
- • Continuously review and remediate vulnerable services with automated visibility across multi-cloud and hybrid environments.



