Threat Advisory

Critical Vulnerability Exploited inTriofoxFile-Sharing Platform

Threat: Vulnerability
Threat Actor Name: -
Threat Actor Type: -
Targeted Region: Global
Alias: -
Threat Actor Region: -
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical unauthenticated access flaw in the Triofox file-sharing platform CVE-2025-12480 with a CVSS score of 9.8 allowed attackers to spoof the HTTP Host header to access the setup page and create an administrative account named Cluster Admin, then exploit the antivirus configuration feature to execute a malicious batch file with SYSTEM-level privileges. This enabled the execution of a PowerShell command to download and run a trojanized UEMS installer, deploying remote access tools such as Zoho Assist and AnyDesk for persistent control. The attackers also leveraged PuTTY and Plink to establish an SSH tunnel redirecting RDP traffic through port 433, concealing their remote activity. The vulnerability stemmed from improper access control validation within the Triofox web interface, and the vendor has released a patch to remediate the issue.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical unauthenticated access flaw in the Triofox file-sharing platform CVE-2025-12480 with a CVSS score of 9.8 allowed attackers to spoof the HTTP Host header to access the setup page and create an administrative account named Cluster Admin, then exploit the antivirus configuration feature to execute a malicious batch file with SYSTEM-level privileges. This enabled the execution of a PowerShell command to download and run a trojanized UEMS installer, deploying remote access tools such as Zoho Assist and AnyDesk for persistent control. The attackers also leveraged PuTTY and Plink to establish an SSH tunnel redirecting RDP traffic through port 433, concealing their remote activity. The vulnerability stemmed from improper access control validation within the Triofox web interface, and the vendor has released a patch to remediate the issue.[emaillocker id="1283"]

RECOMMENDATION:

We strongly recommend you update Triofox file-sharing platform to below version link: https://access.triofox.com/releases_history/

REFERENCES:

The following reports contain further technical details:
https://securityonline.info/critical-triofox-zero-day-cve-2025-12480-under-active-exploit-host-header-bypass-allows-unauthenticated-admin-takeover/

[/emaillocker]
crossmenu