CRITICAL
CVE-2025-54948
CVSS
9.8
KEV
Description
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.
Summary dbcve.org
A pre-authentication remote code execution vulnerability exists in the Trend Micro Apex One on-premise management console. An unauthenticated remote attacker can exploit this by uploading malicious code to the affected system, leading to arbitrary command execution with elevated privileges.
Mitigation
Apply the vendor-supplied patch or update to the latest version of Trend Micro Apex One. If immediate patching is not possible, restrict network access to the management console using firewall rules or VPN access controls.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
22.04%
Probability of exploitation in next 30 days
97.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.