CVE-2025-12480
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
- Published Nov 10, 2025
- CVSS 9.1 critical
- 95.4% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- Public exploit code is available
- A fix is available
Affected software
In the news
- CVE-2026-20079 - Cisco FMC Authentication Bypass RCE Analysis VulnCheck Blog ·
- Herding Cats: Recent Cisco SD-WAN Manager Vulnerabilities VulnCheck Blog ·
- Making Serialization Gadgets by Hand - Java VulnCheck Blog ·
- Tales from the Exploit Mines: Gladinet Triofox CVE-2025-12480 RCE VulnCheck Blog ·