CVE-2025-30406
Last modified
CVE-2025-30406 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to achieve remote code execution. CISA has confirmed active exploitation in the wild. EPSS estimates a 92.73% chance of exploitation in the next 30 days.
Description
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to achieve remote code execution. NOTE: a CentreStack admin can manually delete the machineKey defined in portal\web.config.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gladinet | Centrestack | < 16.4.10315.56368 |
References
- https://gladinetsupport.s3.us-east-1.amazonaws.com/gladinet/securityadvisory-cve-2005.pdfMitigation, Patch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-30406US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-30406?
How severe is CVE-2025-30406?
How do I fix CVE-2025-30406?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-30400Use after free in Windows DWM allows an authorized attacker …7.8
- CVE-2025-30401A spoofing issue in WhatsApp for Windows prior to version 2.…6.7
- CVE-2025-30402A heap-buffer-overflow vulnerability in the loading of Execu…8.1
- CVE-2025-30403A heap-buffer-overflow vulnerability is possible in mvfst vi…8.1
- CVE-2025-30404An integer overflow vulnerability in the loading of ExecuTor…9.8
- CVE-2025-30405An integer overflow vulnerability in the loading of ExecuTor…9.8
- CVE-2025-30407Local privilege escalation due to a binary hijacking vulnera…6.3
- CVE-2025-30408Local privilege escalation due to insecure folder permission…6.7
- CVE-2025-30409Denial of service due to allocation of resources without lim…5.5
- CVE-2025-3041A vulnerability classified as critical has been found in Pro…9.8
- CVE-2025-30410Sensitive data disclosure and manipulation due to missing au…9.8
- CVE-2025-30411Sensitive data disclosure and manipulation due to improper a…10
Are you affected by CVE-2025-30406?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
