The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Yes, some Gladinet server flaws can lead to remote code execution (RCE), but the reports concern different products and different CVEs. CISA’s July 30, 2026 CentreStack summary describes five vulnerabilities, including unauthenticated attack chains that can reach RCE. Separately, Mandiant documented exploitation of Triofox CVE-2025-12480 in 2025. A Canadian advisory dated July 30, 2026 identifies CentreStack versions before 17.5 as affected, while CISA gives issue-specific cutoffs ranging from versions before 17.2 to versions before 17.5.
CentreStack and Triofox are separate cases
CentreStack and Triofox are Gladinet file-sharing and remote-access products, but their security findings should not be combined. The CentreStack issues summarized by CISA use 2026 CVE identifiers and were published in a July 30, 2026 summary. The Triofox incident involves CVE-2025-12480 and Mandiant’s report of exploitation beginning as early as August 24, 2025.
A vulnerability in one product does not establish that the other product has the same flaw, affected version boundary, or remediation.
What CISA reported for CentreStack
CISA described five CentreStack vulnerabilities. Their impacts differ; labeling all five simply as “RCE bugs” would be inaccurate.
#1 Best Overall
- Entry-level NAS Personal Storage:UGREEN NAS DH2300 is your first and best NAS made easy. It is designed for beginners who want a simple, private way to store videos, photos and personal files, which is intuitive for users moving from cloud storage or external drives and move away from scattered date across devices. This entry-level NAS 2-bay perfect for personal entertainment, photo storage, and easy data backup (doesn't support Docker or virtual machines).
- Set Your Devices Free, Expand Your Digital World: This unified storage hub supports massive capacity up to 64TB.*Storage drives not included. Stop Deleting, Start Storing. You can store 22 million 3MB images, or 2 million 30MB songs, or 43K 1.5GB movies or 67 million 1MB documents! UGREEN NAS is a better way to free up storage across all your devices such as phones, computers, tablets and also does automatic backups across devices regardless of the operating system—Window, iOS, Android or macOS.
- The Smarter Long-term Way to Store: Unlike cloud storage with recurring monthly fees, a UGREEN NAS enclosure requires only a one-time purchase for long-term use. For example, you only need to pay $459.98 for a NAS, while for cloud storage, you need to pay $719.88 per year, $2,159.64 for 3 years, $3,599.40 for 5 years. You will save $6,738.82 over 10 years with UGREEN NAS! *NAS cost based on DH2300 + 12TB HDD; cloud cost based on 12TB plan (e.g. $59.99/month).
- Blazing Speed, Minimal Power: Equipped with a high-performance processor, 1GbE port, and 4GB RAM on Board, this NAS handles multiple tasks with ease. File transfers reach up to 125MB/s—a 1GB file takes only 8 seconds. Don't let slow clouds hold you back; they often need over 100 seconds for the same task. The difference is clear.
- Let AI Better Organize Your Memories: UGREEN NAS uses AI to tag faces, locations, texts, and objects—so you can effortlessly find any photo by searching for who or what's in it in seconds. It also automatically finds and deletes similar or duplicate photo, backs up live photos and allows you to share them with your friends or family with just one tap. Everything stays effortlessly organized, powered by intelligent tagging and recognition.
| CVE | Mechanism | Documented impact |
|---|---|---|
| CVE-2026-54363 | A hardcoded cryptographic key enables token forging. | An unauthenticated attack chain can lead to remote code execution. |
| CVE-2026-54367 | Authentication bypass affecting account settings. | Unauthorized account-setting changes; the summary does not characterize this issue itself as an RCE. |
| CVE-2026-54368 | SQL injection. | Arbitrary file writing that can be used in a path to remote code execution. |
| CVE-2026-54365 | Unauthenticated deserialization. | Creation of local operating-system accounts. |
| CVE-2026-54366 | XML external entity (XXE) processing. | File exfiltration. |
The RCE-relevant entries are therefore CVE-2026-54363 and CVE-2026-54368. The other three still represent serious compromise or disclosure risks even where RCE is not the stated impact.
Which CentreStack versions are affected?
The Canadian Centre for Cyber Security’s advisory AV26-765, dated July 30, 2026, gives a product-level boundary of CentreStack versions prior to 17.5. CISA’s entries use issue-specific boundaries, with the cutoffs spanning versions before 17.2 through versions before 17.5.
That means an administrator should not rely on a product name or a single broad version statement. Record the exact CentreStack build, identify which CVEs apply to that build, and compare it with Gladinet’s current security and release guidance. The advisory recommends reviewing the vendor information and applying updates as they become available.
Rank #2
- 【Advanced Home Data & Media Hub】For advanced home users who need phone backup, file storage, and centralized data management. Centralize family photos, 4K videos, movies, computer backups, and personal files in one place while running multiple apps for home entertainment and everyday data management. Suitable for households with growing digital libraries and multiple NAS use cases.
- 【Built for Creators, Media Servers & Advanced Apps】Powered by the Intel N100 Quad-Core CPU, 8GB DDR5 RAM, 2.5GbE networking, and dual M.2 NVMe slots, DXP2800 handles large files and heavier workloads with ease. Run Docker, virtual machines, and media server applications compatible with Plex—ideal for content creators, tech enthusiasts, and advanced home users managing 4K videos, RAW photos, personal media libraries, and multiple NAS apps.
- 【Up to 80TB for Growing Digital Libraries】 Supports up to 80TB of storage using two HDD bays and two M.2 NVMe SSD slots for family photos, movies, RAW photos, 4K videos, work files, and device backups. AI photo management supports recognition of people, objects, scenes, and locations, album organization, and duplicate photo detection. HDDs and SSDs are not included.
- 【AI-powered Home Surveillance】Turn DXP2800 into a centralized home surveillance hub by connecting compatible network cameras and storing recordings locally on your NAS. AI-powered features include Face Recognition, People Detection, and Pet Detection, helping advanced home users review important events more efficiently while managing home surveillance and personal data in one place.
- 【One data Center Across Your Devices】Keep files from desktops, laptops, phones, tablets, and other devices together instead of scattered across cloud accounts and external drives. Access, back up, organize, and share data across Windows, macOS, Android, iOS, web browsers, and compatible smart TVs—ideal for creators and advanced home users working across multiple devices.
What happened with Triofox CVE-2025-12480?
Mandiant reported observing exploitation of Triofox CVE-2025-12480 as early as August 24, 2025. In the activity it investigated, the flaw allowed unauthenticated access to configuration pages. The observed attackers created a native administrator account and abused Triofox’s built-in antivirus feature to achieve code execution.
Mandiant identified Triofox version 16.7.10368.56560 as the mitigation release for the activity described in its report. That version reference belongs to this specific Triofox incident; it is not a CentreStack version and should not be treated as a fix for the CentreStack CVEs.
Was exploitation confirmed in the wild?
Yes, Mandiant documented real-world exploitation of Triofox CVE-2025-12480 in the incident described above. That is evidence of exploitation for that Triofox vulnerability, not proof that every Triofox or CentreStack deployment was attacked.
Rank #3
- Value NAS with RAID for centralized storage and backup for all your devices. Check out the LS 700 for enhanced features, cloud capabilities, macOS 26, and up to 7x faster performance than the LS 200.
- Connect the LinkStation to your router and enjoy shared network storage for your devices. The NAS is compatible with Windows and macOS*, and Buffalo's US-based support is on-hand 24/7 for installation walkthroughs. *Only for macOS 15 (Sequoia) and earlier. For macOS 26, check out our LS 700 series.
- Subscription-Free Personal Cloud – Store, back up, and manage all your videos, music, and photos and access them anytime without paying any monthly fees.
- Storage Purpose-Built for Data Security – A NAS designed to keep your data safe, the LS200 features a closed system to reduce vulnerabilities from 3rd party apps and SSL encryption for secure file transfers.
- Back Up Multiple Computers & Devices – NAS Navigator management utility and PC backup software included. NAS Navigator 2 for macOS 15 and earlier. You can set up automated backups of data on your computers.
The CentreStack material establishes vulnerable mechanisms and potential impacts. It does not, by itself, establish a victim count, prevalence rate, or exploitation of each CentreStack CVE. No population statistic should be inferred from the number of CVEs.
How administrators should respond
1. Identify the product and exact build
Confirm whether the deployment is CentreStack or Triofox, record the complete installed version, and note whether its web interface is reachable from the internet. Do not substitute a CentreStack assessment for a Triofox assessment, or vice versa.
2. Match the build to the specific advisory
For CentreStack, check each CISA CVE against the installed build because the affected thresholds differ by issue. For Triofox, compare the deployment with the mitigation information associated with CVE-2025-12480 and Gladinet’s current guidance.
Rank #4
- Value NAS with RAID for centralized storage and backup for all your devices. Check out the LS 700 for enhanced features, cloud capabilities, macOS 26, and up to 7x faster performance than the LS 200.
- Connect the LinkStation to your router and enjoy shared network storage for your devices. The NAS is compatible with Windows and macOS*, and Buffalo's US-based support is on-hand 24/7 for installation walkthroughs. *Only for macOS 15 (Sequoia) and earlier. For macOS 26, check out our LS 700 series.
- Subscription-Free Personal Cloud – Store, back up, and manage all your videos, music, and photos and access them anytime without paying any monthly fees.
- Storage Purpose-Built for Data Security – A NAS designed to keep your data safe, the LS200 features a closed system to reduce vulnerabilities from 3rd party apps and SSL encryption for secure file transfers.
- Back Up Multiple Computers & Devices – NAS Navigator management utility and PC backup software included. NAS Navigator 2 for macOS 15 and earlier. You can set up automated backups of data on your computers.
3. Apply the vendor’s available update or mitigation
Use Gladinet’s current security and release documentation rather than assuming that a version boundary from the July 30, 2026 advisory describes today’s complete patch status. If an immediate update is not possible, reduce unnecessary internet exposure and restrict administrative access while the risk is assessed.
4. Investigate signs consistent with the documented attack paths
- Unexpected native administrator or local operating-system accounts.
- Unrecognized changes to account settings or configuration pages.
- Unexpected file creation or modification that could indicate SQL-injection-assisted file writing.
- Abnormal use of the built-in antivirus feature in a Triofox environment.
- Unexpected file reads or outbound transfers that could fit an XXE-related disclosure.
Preserve relevant server, identity, and network evidence before deleting accounts or rebuilding systems. If compromise is suspected, involve your incident-response or managed-detection provider; Mandiant’s report describes investigation and containment of a Triofox compromise, not a routine upgrade procedure.
5. Validate recovery
After remediation, verify the exact running build, rotate credentials or tokens where compromise is possible, review newly created accounts, and continue monitoring for repeat access. Treat a server as potentially compromised until investigation supports a clean conclusion.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsBest Value
- Value NAS with RAID for centralized storage and backup for all your devices. Check out the LS 700 for enhanced features, cloud capabilities, macOS 26, and up to 7x faster performance than the LS 200.
- Connect the LinkStation to your router and enjoy shared network storage for your devices. The NAS is compatible with Windows and macOS*, and Buffalo's US-based support is on-hand 24/7 for installation walkthroughs. *Only for macOS 15 (Sequoia) and earlier. For macOS 26, check out our LS 700 series.
- Subscription-Free Personal Cloud – Store, back up, and manage all your videos, music, and photos and access them anytime without paying any monthly fees.
- Storage Purpose-Built for Data Security – A NAS designed to keep your data safe, the LS200 features a closed system to reduce vulnerabilities from 3rd party apps and SSL encryption for secure file transfers.
- Back Up Multiple Computers & Devices – NAS Navigator management utility and PC backup software included. NAS Navigator 2 for macOS 15 and earlier. You can set up automated backups of data on your computers.
What remains unknown
The dated advisories above do not establish whether Gladinet published additional advisories or fixes after July 30, 2026, nor do they establish the current exposure of a particular installation. Before declaring a server protected, verify the latest Gladinet guidance, the precise installed version, external exposure, and evidence from your own environment.
Bottom line
Gladinet’s CentreStack findings include unauthenticated paths to RCE, arbitrary-file-writing-to-RCE risk, authentication bypass, local account creation, and file disclosure. Triofox is a separate case: Mandiant documented exploitation of CVE-2025-12480 and named version 16.7.10368.56560 as the mitigation release for that investigated activity. Identify the product first, map the exact build to the correct CVE, update using current vendor guidance, and investigate for compromise rather than assuming that every Gladinet server shares one vulnerability.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

