By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: CentreStack RCE exploited as zero-day to breach file sharing servers
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > CentreStack RCE exploited as zero-day to breach file sharing servers
Tech News

CentreStack RCE exploited as zero-day to breach file sharing servers

By admin 3 Min Read
Share
SHARE

Hackers exploited a vulnerability in Gladinet CentreStack’s secure file-sharing software as a zero-day since March to breach storage servers

Gladinet CentreStack is an enterprise file-sharing and access platform that turns on-premise file servers (like Windows servers with SMB shares) into secure, cloud-like file systems supporting remote access to internal file shares, file syncing and sharing, multi-tenant deployments, and integration with Active Directory.

The company claims the product is used by thousands of businesses across 49 countries, including enterprises with Windows-based file servers, MSPs hosting file services for multiple clients, and various organizations that need cloud-like access without cloud migration.

The flaw, tracked as CVE-2025-30406, is a deserialization vulnerability impacting Gladinet CentreStack versions up to 16.1.10296.56315. Exploitation in the wild has been observed since March 2025.

The issue stems from using a hardcoded machineKey in the CentreStack portal’s configuration (web.config). If an attacker knows this key, they can craft a malicious serialized payload that the server will trust and execute.

According to the vendor’s advisory, the improperly protected key secures ASP.NET ViewState, which, if forged, can allow attackers to bypass integrity checks, inject arbitrary serialized objects, and eventually execute code on the server.

Fix and mitigations available

Gladinet released a security fix for CVE-2025-30406 on April 3, 2025, with versions 16.4.10315.56368, 16.3.4763.56357 (Windows), and 15.12.434 (macOS).

The vendor recommends that all users upgrade to the latest version for their platforms as soon as possible, or manually rotate the ‘machineKey’ in both ‘rootweb.config’ and ‘portalweb.config.’

“Exploitation has been observed in the wild. We strongly recommend updating to the patched version, which improves key management and mitigates exposure,” advises Gladinet.

“For customers who cannot update immediately, rotating the machineKey values is a recommended interim mitigation.”

Those who perform machineKey rotation on their environment must ensure consistency across nodes in multi-server deployments to avoid operational problems and restart IIS after changes for the mitigations to apply.

CISA has added CVE-2025-30406 to its Known Exploited Vulnerability catalog but has not indiciated it has been exploited by ransomware gangs.

However, given the nature of the product, it is likely being exploited for data theft attacks.

These types of flaws have historically been targeted by the Clop ransomware gang, which has expertise in exploiting file-sharing systems. Previous Clop data theft attacks targeted the Cleo, MOVEit Transfer, GoAnywhere MFT, SolarWinds Serv-U, and Accelion FTA secure file transfer platforms.

The U.S. agency has given impacted state and federal organizations until April 29, 2025, to apply security updates and mitigations or stop using the product.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

You Might Also Like

Apple AI Pin Specs Leak: Dual Cameras, No Screen & More

The diverse responsibilities of a principal software engineer

OpenAI Backs Bill That Would Limit Liability for AI-Enabled Mass Deaths or Financial Disasters

Google’s Fitbit Tease has me More Excited for Garmin’s Whoop Rival

Why the TCL NXTPAPER 14 Is One of the Best Tablets for Musicians and Sheet Music Reading

TAGGED: Actively Exploited, CISA, File sharing, Gladinet CentreStack, Hardcoded Password, KEV, Remote Code Execution, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Harry Brook makes England promise as new captain gives up £550k payday
Next Article LLaMA 4 Maverick Review : Strengths, Weaknesses & Real-World Performance
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
Business
Apple AI Pin Specs Leak: Dual Cameras, No Screen & More
Tech News
A ‘glass-like’ battlefield: German Army chief on the future of warfare
World News
Polymarket Sees Record $153M Daily Volume After Chainlink Integration
Crypto
Natasha Lyonne Then & Now: See Before & After Photos of the Actress Here
Celebrity
Cult Hit Doki Doki Literature Club Fights Removal From Google Play Store Over ‘Depiction Of Sensitive Themes’
Gaming News
Dead as Disco Launches Into Early Access on May 5th, Groovy New Gameplay Released
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
April 10, 2026
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?