CVE-2025-30406 affects Gladinet CentreStack and Triofox through hardcoded ASP.NET machineKey values used to protect ViewState integrity. An attacker who knows the key can forge a malicious serialized ViewState payload that passes integrity verification and executes arbitrary code during server-side deserialization. CentreStack versions below 16.4.10315.56368 and Triofox versions below 16.4.10317.56372 are affected. Exploitation was observed in the wild beginning in March 2025.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a Proof-of-Concept (PoC) exploit for CVE-2025-30406, a ViewState deserialization vulnerability in ASP.NET applications. The exploit consists of two main Python scripts: 1. 'exploit.py' is the primary exploit script. It uses ysoserial to generate a malicious ViewState payload with a hardcoded validation key and generator. The payload executes an arbitrary command on the target server. If a callback URL is provided, the command is wrapped in PowerShell to send its output to an attacker-controlled HTTP server via HTTP GET. The script sends the payload to a user-specified vulnerable ASP.NET endpoint via POST, embedding it in the '__VIEWSTATE' parameter. 2. 'server.py' is a simple HTTP server that listens (by default on port 8000) for GET requests containing exfiltrated command output. It displays the output in a styled format with timestamps and colored prompts for readability. The repository also includes a detailed README.md with setup, usage instructions, and ethical warnings. The exploit requires the attacker to know the ViewState validation key and generator for the target application, and to have ysoserial available. The exploit is a POC and not weaponized, as it requires manual setup and hardcoded values. The main attack vector is network-based, targeting vulnerable ASP.NET endpoints over HTTP. Fingerprintable endpoints include the target ASP.NET URL and the attacker's callback server for exfiltration.
This repository contains a single Metasploit module targeting CVE-2025-30406, a critical ViewState deserialization vulnerability in Gladinet CentreStack and Triofox web applications for Windows. The exploit leverages a hardcoded machineKey found in the IIS web.config file, allowing attackers to forge ViewState payloads that pass integrity checks. By sending a specially crafted ViewState parameter to the '/portal/loginpage.aspx' endpoint, the module achieves remote code execution (RCE) on vulnerable servers. The module is weaponized, supporting arbitrary command execution via the Metasploit payload system. The code is written in Ruby and follows standard Metasploit module structure, with clear separation of check, exploit, and payload generation logic. The exploit is network-based and requires the target application to be accessible over HTTP/HTTPS. No static IPs or domains are hardcoded; the main fingerprintable endpoint is the application path and the use of the hardcoded machineKey in the configuration file.
This repository provides a working exploit for CVE-2025-30406, a critical remote code execution vulnerability in Gladinet CentreStack and Triofox (tested on version 16.1.10296.56315 for Windows). The exploit is implemented in C# (.NET 4.7.2) and generates a malicious ViewState payload containing a serialized XAML object (rce.txt) that triggers arbitrary command execution on the target server. The main entry point is Program.cs, which handles ViewState generation and signing. The README provides usage instructions, including how to use ysoserial.net to generate payloads and target the vulnerable endpoint (/portal/loginpage.aspx). The exploit requires knowledge of the ViewState validation key, which is provided in the README for demonstration. The payload can be customized to execute arbitrary commands, either by modifying the XAML or by sending a custom 'cmd' HTTP header. The repository also includes references to public advisories and detection templates. No evidence of fake or detection-only code was found; this is a functional exploit for RCE via .NET deserialization.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
50 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical Gladinet CentreStack/Triofox vulnerability involving a hard-coded cryptographic key (MachineKey) enabling remote code execution; actively exploited and added to CISA KEV.
A critical Gladinet CentreStack/TrioFox vulnerability caused by hardcoded machine keys that enables server-side deserialization and remote code execution.
A critical deserialization vulnerability in Gladinet CentreStack allows attackers who know the portal's hardcoded machineKey to craft serialized payloads that achieve server-side remote code execution. The record lists versions before 16.4.10315.56368 as affected and assigns a CVSS v3.1 score of 9.0. Exploitation occurred in March 2025. Version 16.4.10315.56368 fixes the flaw; administrators can also manually delete the machineKey defined in portal\web.config.
A vulnerability in earlier versions of CentreStack and Triofox where a hardcoded machine key allows remote code execution via ViewState deserialization.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.