Description
Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo, /woshome, /Settings, /schedule, or /DavCache.
Published: 2026-05-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) exposes a set of unsecured HTTP endpoints on TCP port 7878. These endpoints – including /resources, /status, /sysinfo, /woshome, /Settings, /schedule, and /DavCache – can be called without any authentication. Because these paths perform privileged functions, an attacker that can reach the service could trigger those functions remotely, potentially achieving full remote code execution or complete unauthorized control of the managed device. This weakness is classified as CWE‑306, Missing Authentication.

Affected Systems

The vulnerability affects Gladinet Triofox servers running the server agent component that listens on port 7878. No specific product versions are listed in the CVE data, so the full scope of affected releases is not defined. Administrators should confirm that the GladServerAgentService.exe is running on their systems and determine the exact product version if possible.

Risk and Exploitability

The CVSS base score of 9.8 indicates critical severity. The EPSS score is not available, so the current estimate of exploitation likelihood is unknown; however, because the service exposes critical functionality on a publicly reachable port without authentication, the risk of remote exploitation is high. Based on the description, the likely attack vector is remote, network-based HTTP access to the open endpoints. The vulnerability is not listed in the CISA KEV catalog. Combined, the high severity and unrestricted exposure suggest that the vulnerability should be treated with top priority.

Generated by OpenCVE AI on May 27, 2026 at 22:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Block inbound traffic to TCP port 7878 using firewall rules or network segmentation to prevent unauthenticated access.
  • Disable or uninstall the GladServerAgentService.exe if the server is not required to expose this functionality, reducing the attack surface.
  • Contact Gladinet support to obtain a patch or firmware update that enforces authentication on the exposed URLs, and apply the fix as soon as it becomes available.

Generated by OpenCVE AI on May 27, 2026 at 22:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 28 May 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Gladinet
Gladinet triofox
Vendors & Products Gladinet
Gladinet triofox

Wed, 27 May 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 27 May 2026 20:15:00 +0000

Type Values Removed Values Added
Description Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo, /woshome, /Settings, /schedule, or /DavCache.
Title Gladinet Triofox Missing Authentication for Critical Functions
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Gladinet Triofox
cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2026-05-28T03:56:02.086Z

Reserved: 2026-05-11T19:17:42.250Z

Link: CVE-2026-8364

cve-icon Vulnrichment

Updated: 2026-05-27T20:23:54.556Z

cve-icon NVD

Status : Received

Published: 2026-05-27T20:16:43.333

Modified: 2026-05-27T21:16:19.700

Link: CVE-2026-8364

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T03:00:05Z

Weaknesses