Zero-Day Nightmare: CentreStack File Sharing Servers Under Attack Since March


# Zero-Day Vulnerability in Gladinet CentreStack Exploited Since March

A critical security flaw in Gladinet CentreStack’s enterprise file-sharing software has been actively exploited by hackers since March 2025. The vulnerability, tracked as CVE-2025-30406, affects thousands of businesses across 49 countries that use the platform to transform on-premise file servers into secure, cloud-like systems.

## The Vulnerability

The security issue is a deserialization vulnerability affecting Gladinet CentreStack versions up to 16.1.10296.56315. The flaw stems from a hardcoded machineKey in the CentreStack portal’s web configuration file. Attackers who obtain this key can craft malicious serialized payloads that bypass integrity checks and ultimately execute arbitrary code on affected servers.

According to Gladinet’s advisory, the vulnerability compromises ASP.NET ViewState security, allowing attackers to inject arbitrary serialized objects and execute code with server privileges.

## Patches and Mitigations

Gladinet released security fixes on April 3, 2025, with the following patched versions:
– 16.4.10315.56368
– 16.3.4763.56357 (Windows)
– 15.12.434 (macOS)

For organizations unable to update immediately, the vendor recommends manually rotating the ‘machineKey’ in both ‘rootweb.config’ and ‘portalweb.config’ files. Organizations with multi-server deployments must ensure consistency across all nodes and restart IIS after making changes.

## Government Response

The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-30406 to its Known Exploited Vulnerability catalog. Federal and state organizations must apply security updates by April 29, 2025, or discontinue using the product.

While CISA hasn’t confirmed ransomware involvement, the vulnerability likely enables data theft attacks. Similar flaws in file-sharing systems have historically been targeted by threat actors like the Clop ransomware gang, which previously exploited vulnerabilities in Cleo, MOVEit Transfer, GoAnywhere MFT, SolarWinds Serv-U, and Accelion FTA platforms.

Share This Article