HomeData BreachCISA Provides Gladinet and CWP Flaws to KEV Catalog Amid Lively Exploitation...

CISA Provides Gladinet and CWP Flaws to KEV Catalog Amid Lively Exploitation Proof

The U.S. Cybersecurity and Infrastructure Safety Company (CISA) on Tuesday added two security flaws impacting Gladinet and Management Net Panel (CWP) to its Identified Exploited Vulnerabilities (KEV) catalog, citing proof of energetic exploitation within the wild.

The vulnerabilities in query are listed beneath –

  • CVE-2025-11371 (CVSS rating: 7.5) – A vulnerability in information or directories accessible to exterior events in Gladinet CentreStack and Triofox that might lead to unintended disclosure of system information.
  • CVE-2025-48703 (CVSS rating: 9.0) – An working system command injection vulnerability in Management Net Panel (previously CentOS Net Panel) that leads to unauthenticated distant code execution by way of shell metacharacters within the t_total parameter in a filemanager changePerm request.

The event comes weeks after cybersecurity firm Huntress stated it detected energetic exploitation makes an attempt focusing on CVE-2025-11371, with unknown risk actors leveraging the flaw to run reconnaissance instructions (e.g., ipconfig /all) handed within the type of a Base64-encoded payload.

CIS Build Kits

Nevertheless, there are at present no public stories on how CVE-2025-48703 is being weaponized in real-world assaults. Nevertheless, technical particulars of the flaw have been shared by security researcher Maxime Rinaudo in June 2025, shortly after it was patched in model 0.9.8.1205 following accountable disclosure on Could 13.

See also  Classes realized and subsequent steps

“It permits a distant attacker who is aware of a sound username on a CWP occasion to execute pre-authenticated arbitrary instructions on the server,” Rinaudo stated.

In mild of energetic exploitation, Federal Civilian Govt Department (FCEB) businesses are required to use the required fixes by November 25, 2025, to safe their networks.

The addition of the 2 flaws to the KEV catalog follows stories from Wordfence concerning the exploitation of important security vulnerabilities impacting three WordPress plugins and themes –

  • CVE-2025-11533 (CVSS rating: 9.8) – A privilege escalation vulnerability in WP Freeio that makes it doable for an unauthenticated attacker to grant themselves administrative privileges by specifying a person position throughout registration.
  • CVE-2025-5397 (CVSS rating: 9.8) – An authentication bypass vulnerability in Noo JobMonster that makes it doable for unauthenticated attackers to sidestep customary authentication and entry administrative person accounts, assuming social login is enabled on a web site.
  • CVE-2025-11833 (CVSS rating: 9.8) – A scarcity of authorization checks in Put up SMTP that makes it doable for an unauthenticated attacker to view e-mail logs, together with password reset emails, and alter the password of any person, together with an administrator, permitting web site takeover.
See also  The Blind Spot Fueling Fee Skimmer Attacks

WordPress web site customers counting on the aforementioned plugins and themes are really useful to replace them to the most recent model as quickly as doable, use robust passwords, and audit the websites for indicators of malware or the presence of surprising accounts.

- Advertisment -spot_img
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular