macc /
EN FR
Book a meeting
← Back to console
Critical CCB · Belgium CVE-2026-8362

Critical vulnerabilities in Gladinet Triofox

Published

Description

The 3 most critical vulnerabilities are: CVE-2026-8362: Stack-based Buffer Overflow (CWE-121): WOSDefaultHttpModule.dll has a stack buffer overflow when processing a long URL path beginning with /woshome. CVE-2026-8363: Stack-based Buffer Overflow (CWE-121): WOSDeviceDropFolder.dll has a stack buffer overflow when processing a long URL path beginning with /resources. CVE-2026-8364: Missing Authentication for Critical Function (CWE-306): GladServerAgentService.exe accepts unauthenticated HTTP requests to endpoints such as /resources, /Settings, /status, /sysinfo, /woshome, /schedule, and /DavCache; attackers can list/view/add/change/delete Triofox Drive files, alter gsettings.db settings, and potentially trigger authenticated portal communications using the logged-in Server Agent Management