CVE-2025-12480 is an improper access control vulnerability in Gladinet’s Triofox file-sharing and remote-access platform. The flaw allows unauthenticated remote actors to access application configuration/setup pages that should be protected, which can be leveraged to create administrative accounts, manipulate configuration (including the built-in anti-virus handling), upload malicious files, and ultimately execute arbitrary code on affected systems. The issue affects Triofox builds prior to the patched release (mitigated in 16.7.10368.56560); public reporting and threat intelligence indicate a high severity rating and active exploitation in the wild by threat actors.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Affected assets are outlined in this post.
References:

