CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2025-54948

CVSS 9.4v3.1pub. 2025-08-05upd. 2025-10-31

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.

🤖 AI Analysis
How it works

A command injection vulnerability (CWE-78) in the management console allows an attacker to submit malicious code to the vulnerable installation without possessing any credentials. The submitted payload is subsequently executed in the context of the operating system on which the console runs. The attack vector is network-based, requires no user interaction or attacker-side privileges (AV:N/AC:L/PR:N/UI:N).

Impact

An attacker can obtain unauthorized access to sensitive data (including configuration and environment data), partially modify system resources, and cause service unavailability, collectively threatening the confidentiality, integrity, and availability of the protected environment.

Mitigation & patch

Patches available from the vendor should be applied immediately according to references (https://success.trendmicro.com/en-US/solution/KA-0020652). Until updates are deployed, it is recommended to restrict network access to the management console to trusted hosts only and implement enhanced monitoring of logs for unauthorized requests.

Who is affected

Trend Micro Apex One on-premise version – detailed information on vulnerable versions available in vendor references (KA-0020652)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
  • Trendmicro Apex One

    APP
    Trendmicro
    2019

CISA KEV — detailsi

Vendori
Trend Micro
Producti
Apex One
Added to KEVi
August 18, 2025
Remediation deadline (US Federal)i
September 8, 2025(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 8 września 2025
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2022-26871CRITICAL9.8⚠ KEVPL ✓same product

Trend Micro Apex Central — dowolne przesyłanie plików prowadzące do RCE

CVE-2020-8599CRITICAL9.8⚠ KEVPL ✓same product

Trend Micro Apex One / OfficeScan XG — zapis pliku bez uwierzytelnienia i bypass loginu ROOT

CVE-2025-54987CRITICAL9.4PL ✓same product

RCE w Trend Micro Apex One – command injection bez uwierzytelnienia

CVE-2023-32557CRITICAL9.8PL ✓same product

Path Traversal umożliwiający RCE w Trend Micro Apex One

CVE-2023-25143CRITICAL9.8PL ✓same product

RCE poprzez niekontrolowany element ścieżki wyszukiwania w instalatorze Trend Micro Apex One Server