The U.S. Cybersecurity and Infrastructure Safety Company (CISA) on Tuesday added a essential security flaw impacting Gladinet CentreStack to its Recognized Exploited Vulnerabilities (KEV) catalog, citing proof of lively exploitation within the wild.
The vulnerability, tracked as CVE-2025-30406 (CVSS rating: 9.0), considerations a case of a hard-coded cryptographic key that may very well be abused to attain distant code execution. It has been addressed in model 16.4.10315.56368 launched on April 3, 2025.
“Gladinet CentreStack comprises a use of hard-coded cryptographic key vulnerability in the way in which that the applying manages keys used for ViewState integrity verification,” CISA stated. “Profitable exploitation permits an attacker to forge ViewState payloads for server-side deserialization, permitting for distant code execution.”

Particularly, the shortcoming is rooted in using a hard-code “machineKey” within the IIS internet.config file, which allows risk actors with data of “machineKey” to serialize a payload for subsequent server-side deserialization to be able to obtain distant code execution.

There are at the moment no particulars on how the vulnerability is being exploited, the identification of the risk actors exploiting it, and who could be the targets of those assaults. That stated, an outline of the security defect on CVE.org states that CVE-2025-30406 was exploited within the wild in March 2025, indicating its use as a zero-day.
Gladinet, in an advisory, has additionally acknowledged that “exploitation has been noticed within the wild,” urging prospects to use the fixes as quickly as potential. If instant patching is just not an choice, it is suggested to rotate the machineKey worth as a short lived mitigation.