Critical Alert: CISA Reveals Active Exploitation of CentreStack Vulnerability Enabling Remote Attacks


# Critical Vulnerability in Gladinet CentreStack Under Active Exploitation

CISA has added a critical security vulnerability affecting Gladinet CentreStack to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in the wild. The flaw, identified as CVE-2025-30406 with a severe CVSS score of 9.0, involves a hard-coded cryptographic key that can be leveraged to execute remote code.

The vulnerability exists in how CentreStack manages keys used for ViewState integrity verification. Attackers who gain knowledge of the hard-coded “machineKey” in the IIS web.config file can forge ViewState payloads, enabling server-side deserialization attacks that result in remote code execution.

According to CVE.org, this vulnerability was exploited as a zero-day in March 2025. Gladinet has confirmed these exploitations and released a patch in version 16.4.10315.56368 on April 3, 2025.

Organizations using CentreStack are strongly advised to update to the patched version immediately. If patching isn’t immediately possible, administrators should implement the recommended temporary mitigation of rotating the machineKey value.

While details about the threat actors behind these attacks and their targets remain unknown, the critical nature of this vulnerability demands urgent attention from affected organizations.

Share This Article