CRITICAL

CVE-2025-54948

Trendmicro Apex One 2025-08-05 CVSS v3.1
CVSS
9.8
KEV

Description

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.

Summary dbcve.org

A pre-authentication remote code execution vulnerability exists in the Trend Micro Apex One on-premise management console. An unauthenticated remote attacker can exploit this by uploading malicious code to the affected system, leading to arbitrary command execution with elevated privileges.

Mitigation

Apply the vendor-supplied patch or update to the latest version of Trend Micro Apex One. If immediate patching is not possible, restrict network access to the management console using firewall rules or VPN access controls.

Patch Commit

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

22.04%
Probability of exploitation in next 30 days
97.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE