Organizations impacted by the vulnerability were urged to promptly install CentreStack version 16.10.10408.56683, while those that cannot do so have been advised to deactivate the temp handler within the UploadDownloadProxy's Web[.]config file as a mitigation.

Attacks involving CVE-2025-11371 which circumvented fixes for the deserialization flaw, tracked as CVE-2025-30406 enabled the compromise of patched CentreStack instances' Web[.]config files and the extraction of machine keys prior to remote code execution, according to researchers from Huntress, who first reported about the vulnerability.

Additional details on a proof-of-concept exploit for the bug showed that obtained machine keys could be used by threat actors to facilitate forgery of an illicit ViewState payload that could be subjected to later deserialization.