CVE-2025-12480

Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gladinet:triofox:*:*:*:*:*:*:*:*

History

13 Nov 2025, 15:07

Type Values Removed Values Added
References () https://access.triofox.com/releases_history/ - () https://access.triofox.com/releases_history/ - Release Notes
References () https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480 - () https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480 - Exploit, Third Party Advisory
References () https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2025/MNDT-2025-0008.md - () https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2025/MNDT-2025-0008.md - Third Party Advisory
References () https://www.triofox.com/ - () https://www.triofox.com/ - Product
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-12480 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-12480 - US Government Resource
CPE cpe:2.3:a:gladinet:triofox:*:*:*:*:*:*:*:*
First Time Gladinet
Gladinet triofox

12 Nov 2025, 15:15

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-12480 -

10 Nov 2025, 16:15

Type Values Removed Values Added
References
  • () https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480 -

10 Nov 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-10 15:15

Updated : 2025-11-14 02:00


NVD link : CVE-2025-12480

Mitre link : CVE-2025-12480

CVE.ORG link : CVE-2025-12480


JSON object : View

Products Affected

gladinet

  • triofox
CWE
CWE-284

Improper Access Control