CVE-2025-12480: Triofox HTTP Host Header Authentication Bypass Exploited by UNC6485 for SYSTEM-Level Code Execution
CVE-2025-12480 (TL-2026-1507) is a high-severity software vulnerability scored CVSS 9.1, first published 2026-07-19. It is attributed to UNC6485 with medium confidence, affects Gladinet Triofox, references 1 CVE (CVE-2025-12480), maps to 23 MITRE ATT&CK techniques (T1021.001, T1021.004, T1036.005), and is covered by 9 detection rules and 24 indicators of compromise.
Key facts for TL-2026-1507
- Threat ID
- TL-2026-1507
- Severity
- HIGH
- CVSS
- 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-19
- Last reviewed
- 2026-07-19
- Attribution
- UNC6485
- Attribution confidence
- MEDIUM
- Motivation
- UNKNOWN
- Target sectors
- msp, enterprise, file-sharing-infrastructure
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in CVE-2025-12480
Malware and tooling: AnyDesk, Plink (PuTTY Link), Zoho Assist
Google Threat Intelligence Group (GTIG) and Mandiant documented active exploitation of CVE-2025-12480, a CVSS 9.1 improper access control flaw in Gladinet's Triofox file-sharing platform caused by a flawed HTTP Host header check in CanRunCriticalPage(). Threat cluster UNC6485 has exploited the flaw since Aug. 24, 2025 to reach exposed admin setup pages, create a rogue admin account, and abuse Triofox's anti-virus engine configuration to execute arbitrary batch scripts under SYSTEM context, followed by deployment of Zoho UEMS/Zoho Assist, AnyDesk, and a Plink/PuTTY SSH reverse tunnel for persistence and C2.
How CVE-2025-12480 works
CVE-2025-12480 is an improper access control vulnerability (CWE-284) in Gladinet Triofox versions prior to 16.7.10368.56560. The root cause lies in the CanRunCriticalPage() method of GladPageUILib.GladBasePage (C:\Program Files (x86)\Triofox\portal\bin\GladPageUILib.dll), which decides whether a request may reach sensitive initial-setup pages (AdminDatabase.aspx, AdminAccount.aspx, InitAccount.aspx, CommitPage.aspx). The check trusts the ASP.NET Request.Url.Host value -- which is derived directly from the attacker-controllable HTTP Host header -- and automatically grants access whenever that value equals "localhost", without verifying the request actually originated from the loopback interface. If no TrustedHostIp is configured in web.config, the Host-header check is the only protection on these pages, meaning any unauthenticated remote attacker can spoof the Host header to localhost and reach setup/administration functionality on an already-configured, internet-facing Triofox instance.
Google Threat Intelligence Group (GTIG) and Mandiant Threat Defense observed the financially/access-motivated cluster UNC6485 exploiting this flaw in the wild beginning August 24, 2025 (Mandiant's KEV justification separately cites an August 14, 2025 campaign start estimate) -- roughly two and a half months before the November 10, 2025 public disclosure and the November 12, 2025 CISA KEV addition. This places CVE-2025-12480 in a growing pattern of Gladinet/Triofox vulnerabilities (following CVE-2025-30406 and CVE-2025-11371) weaponized against MSP and enterprise file-sharing infrastructure.
The observed attack chain: (1) the attacker sends a crafted HTTP GET to /management/CommitPage.aspx and related setup endpoints with the Host header set to "localhost", bypassing CanRunCriticalPage() and reaching AdminDatabase.aspx; (2) the attacker completes the setup workflow via InitAccount.aspx to create a rogue native administrator account named "Cluster Admin" with attacker-chosen credentials, requiring no prior authentication; (3) using the new admin account, the attacker abuses a built-in product feature -- Triofox's configurable anti-virus engine path -- by pointing it at an attacker-supplied batch script (C: riofox\centre_report.bat); (4) when a file is subsequently uploaded/scanned, GladinetCloudMonitor.exe invokes the configured "AV engine" via cmd.exe (C:\Windows\system32\cmd.exe /c ""c: riofox\centre_report.bat" C:\Windows\TEMP\eset_temp\ESET638946159761752413.av"), executing the attacker's script with SYSTEM-level privileges and achieving full remote code execution; (5) the script launches a PowerShell downloader (-NoProfile -ExecutionPolicy Bypass) that retrieves a disguised Zoho Unified Endpoint Management System (UEMS) installer from an attacker-controlled IP (84.200.80[.]252) to C:\Windows\appcompat\, then silently installs it; (6) the Zoho UEMS agent is used to deploy legitimate dual-use remote access tools -- Zoho Assist and AnyDesk -- for hands-on-keyboard access and persistence; (7) the operator uses Zoho Assist to enumerate active SMB sessions and local/domain user accounts, and attempts to change existing account passwords and add accounts to the local Administrators and Domain Admins groups; (8) for covert command-and-control and RDP access, the actor downloads renamed copies of Plink (PuTTY Link, saved as sihosts.exe) and the PuTTY SSH client (saved as silcon.exe) from the.earth[.]li to C:\windows emp\, then establishes an outbound SSH reverse tunnel over TCP/433 to C2 server 216.107.136[.]46, forwarding remote port 17400 to local 127.0.0.1:3389 (RDP), giving the actor persistent RDP access to the compromised host through an encrypted, firewall-evading SSH channel. Mandiant observed a return login from a second IP (65.109.204[.]197) after a dormancy period, suggesting the access was retained and revisited.
Mandiant Threat Defense detected the intrusion via a composite detection identifying remote access utility installation combined with staging-directory activity, and contained the incident within 16 minutes of investigation initiation. Gladinet patched the flaw in Triofox 16.7.10368.56560 (released July 26, 2025) by preventing setup/configuration pages from remaining reachable once initial setup is complete; because exploitation began after the patch existed but organizations had not yet updated, this is also a patch-lag/n-day exploitation case, not a true zero-day at time of active abuse. CISA added CVE-2025-12480 to the Known Exploited Vulnerabilities (KEV) catalog on November 12, 2025 with a federal remediation action-due date of December 3, 2025.
MITRE ATT&CK techniques used in TL-2026-1507
Lateral Movement
T1021.001 Remote Desktop Protocol; T1021.004 SSH; T1570 Lateral Tool Transfer
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1078.003 Local Accounts; T1140 Deobfuscate/Decode Files or Information
Discovery
T1040 Network Sniffing; T1049 System Network Connections Discovery; T1087.001 Local Account; T1087.002 Domain Account
Execution
T1059.001 PowerShell; T1059.003 Windows Command Shell
Command and Control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1572 Protocol Tunneling
Privilege Escalation
T1098 Account Manipulation; T1548 Abuse Elevation Control Mechanism
persistence
T1098.007 Additional Local or Domain Groups
Persistence
T1133 External Remote Services; T1136.001 Local Account
Initial Access
T1190 Exploit Public-Facing Application
Impact
Affected products and versions in CVE-2025-12480
- Gladinet — Triofox
Vulnerable versions: 16.4.10317.56372; all versions prior to 16.7.10368.56560
Fixed in: 16.7.10368.56560
Remediation for CVE-2025-12480
Patches
- Upgrade Triofox to version 16.7.10368.56560 (released 2025-07-26) or later
Immediate actions
- Restrict network access to Triofox management/setup endpoints (/management/AdminDatabase.aspx, /management/AdminAccount.aspx, /management/InitAccount.aspx, /management/CommitPage.aspx) to trusted internal networks only
- Review all Triofox local admin accounts for unauthorized/unexpected entries, especially accounts named similarly to 'Cluster Admin'
- Audit the configured anti-virus engine path in Triofox settings for unauthorized/non-standard executables or scripts
- Block outbound connections to known UNC6485 C2 IPs: 85.239.63.37, 65.109.204.197, 84.200.80.252, 216.107.136.46
- Hunt for renamed Plink/PuTTY binaries (sihosts.exe, silcon.exe) and outbound SSH traffic on TCP/433
- Hunt for unauthorized AnyDesk and Zoho Assist installations, especially staged via C:\Windows\appcompat\ or C:\Windows\Temp\
Workarounds
- If patching is delayed, place Triofox management endpoints behind a reverse proxy or firewall rule that strips/normalizes client-supplied Host headers before they reach the application
- Disable or tightly restrict the anti-virus engine integration feature until patched
Longer-term hardening
- Deploy EDR with behavioral detection for GladinetCloudMonitor.exe spawning cmd.exe or powershell.exe
- Implement network segmentation isolating internet-facing file-sharing appliances from internal Active Directory infrastructure
- Enforce allow-listing of remote access/remote monitoring tools (Zoho Assist, AnyDesk) with alerting on unauthorized installs
- Configure TrustedHostIp in Triofox web.config and validate Host-header trust logic is not the sole access gate on any exposed appliance
CVEs associated with CVE-2025-12480
CVE-2025-12480
Weaknesses (CWE) in CVE-2025-12480
CWE-284
Timeline of CVE-2025-12480
- Gladinet releases Triofox 16.7.10368.56560, which fixes CVE-2025-12480 by preventing setup/configuration pages from remaining reachable after initial setup.
- Attacker deploys renamed Plink (sihosts.exe) and PuTTY (silcon.exe) binaries sourced from the.earth.li, establishing an SSH reverse tunnel over TCP/433 to C2 server 216.107.136.46, forwarding RDP (3389) externally.
- Attacker uses Zoho Assist to enumerate active SMB sessions and local/domain user accounts, and attempts password changes and additions to local Administrators/Domain Admins groups.
- PowerShell downloader retrieves a disguised Zoho UEMS installer from 84.200.80.252, which is used to deploy Zoho Assist and AnyDesk remote access tools for persistence.
- Using the rogue admin account, attacker configures Triofox's anti-virus engine path to point to a malicious batch script (centre_report.bat), later executed under SYSTEM privileges via GladinetCloudMonitor.exe/cmd.exe.
- Attacker spoofs the HTTP Host header to 'localhost' to reach AdminDatabase.aspx/InitAccount.aspx and creates a rogue native administrator account named 'Cluster Admin'.
- UNC6485 begins actively exploiting CVE-2025-12480 in the wild, per GTIG/Mandiant, targeting unpatched internet-facing Triofox instances (Mandiant's KEV justification cites an alternate campaign-start estimate of 2025-08-14).
- Mandiant initiates contact with Gladinet regarding the suspected vulnerability (per MNDT-2025-0008 disclosure timeline).
- Vulnerability confirmed by Mandiant as an improper access control flaw (CWE-284).
- Gladinet acknowledges Mandiant's findings.
- Google Threat Intelligence Group and Mandiant publish the joint blog post disclosing CVE-2025-12480, UNC6485 activity, IOCs, and detection rules.
- CISA adds CVE-2025-12480 to the Known Exploited Vulnerabilities (KEV) catalog, setting a federal remediation deadline of 2025-12-03.
- CISA BOD 22-01 remediation action-due date for federal agencies to patch or mitigate CVE-2025-12480.
Sources cited for CVE-2025-12480
- Unauthenticated Remote Access via Triofox Vulnerability CVE-2025-12480
- CVE-2025-12480 Detail - NVD
- CVE Record - CVE-2025-12480
- CISA Known Exploited Vulnerabilities Catalog - CVE-2025-12480
- MNDT-2025-0008 Vulnerability Disclosure
- CVE-2025-12480 Triofox RCE Vulnerability
- Triofox Unauthenticated Access Control Vulnerability (CVE-2025-12480)
- Attackers exploited another Gladinet Triofox vulnerability (CVE-2025-12480)
- Hackers Exploit Critical Flaw in Triofox File Sharing Product
- Triofox Release History
- CVE-2025-12480
Threats related to CVE-2025-12480
- CVE-2026-50641: Plaintext Password Storage in Streamsoft Business Intelligence
- LegacyHive: Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day PoC (Unpatched, No CVE)
- Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2 Campaign
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV
Detection coverage for TL-2026-1507
As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1507 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1507
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.