Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
References
| Link | Resource |
|---|---|
| https://access.triofox.com/releases_history/ | Release Notes |
| https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480 | Exploit Third Party Advisory |
| https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2025/MNDT-2025-0008.md | Third Party Advisory |
| https://www.triofox.com/ | Product |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-12480 | US Government Resource |
Configurations
History
13 Nov 2025, 15:07
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://access.triofox.com/releases_history/ - Release Notes | |
| References | () https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480 - Exploit, Third Party Advisory | |
| References | () https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2025/MNDT-2025-0008.md - Third Party Advisory | |
| References | () https://www.triofox.com/ - Product | |
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-12480 - US Government Resource | |
| CPE | cpe:2.3:a:gladinet:triofox:*:*:*:*:*:*:*:* | |
| First Time |
Gladinet
Gladinet triofox |
12 Nov 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
10 Nov 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
10 Nov 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-10 15:15
Updated : 2025-11-14 02:00
NVD link : CVE-2025-12480
Mitre link : CVE-2025-12480
CVE.ORG link : CVE-2025-12480
JSON object : View
Products Affected
gladinet
- triofox
CWE
CWE-284
Improper Access Control
