CVE-2025-12480 Details
Description
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
An improper access control vulnerability has been identified in Triofox versions prior to 16.7.10368.56560. This vulnerability allows unauthorized access to initial setup pages, even after the setup process is complete. The issue arises from an HTTP Host header attack, where an attacker can bypass access controls and reach the setup page by manipulating the Host header value.
Users are advised to update Triofox to version 16.7.10368.56560 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-12480 | CISA-ADP | US Government Resource |
| https://access.triofox.com/releases_history/ | [email protected] | Release Notes |
| https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480 | [email protected] | ExploitThird Party Advisory |
| https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2025/MNDT-2025-0008.md | [email protected] | Third Party Advisory |
| https://www.triofox.com/ | [email protected] | Product |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Gladinet Triofox Improper Access Control Vulnerability | Nov 12, 2025 | Dec 3, 2025 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gladinet triofox | < 16.7.10368.56560 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 14, 2025 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Nov 13, 2025 | Initial Analysis | [email protected] |
| Nov 12, 2025 | CVE Modified | CISA-ADP |
| Nov 10, 2025 | CVE Modified | [email protected] |
| Nov 10, 2025 | New CVE Received | [email protected] |