CVE-2025-12480: Gladinet Triofox Improper Access Control Vulnerability

Critical severity, CVSS 9.1. Actively exploited: in CISA KEV since 2025-11-12. EPSS: 95.4% chance of exploitation in the next 30 days.

Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.

Affected products

  • Gladinet Triofox: before 16.7.10368.56560 (fixed in 16.7.10368.56560)

Published 2025-11-10. Last modified 2026-06-17.