← KEV catalog
CISA known exploited vulnerability

CVE-2025-12480

Gladinet Triofox Improper Access Control Vulnerability

SOURCE FACT

Gladinet · Triofox

Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete.

Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA notes

https://access.triofox.com/releases_history ; https://nvd.nist.gov/vuln/detail/CVE-2025-12480

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?