CVE-2025-30406

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 3, 2025
Updated: Apr 22, 2025
CWE ID 321
CWE ID 798

Summary

CVE-2025-30406 is a deserialization vulnerability affecting Gladinet CentreStack versions prior to 16.4.10315.56368. Hackers can exploit this issue, which stems from the CentreStack portal's hardcoded machineKey, to perform server-side deserialization and execute arbitrary code. This vulnerability was exploited in the wild in March 2025. CentreStack administrators have the ability to manually delete the machineKey defined in portal\web.config to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share