CRITICAL🇵🇱 Wersja polska

CVE-2025-54987

CVSS 9.4v3.1pub. 2025-08-05upd. 2025-08-12

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is essentially the same as CVE-2025-54948 but targets a different CPU architecture.

🤖 AI Analysis
How it works

The vulnerability is classified as command injection (CWE-78) and affects the management console of the Apex One product in the locally installed version (on-premise). An attacker, without needing any credentials (pre-authenticated), can send a crafted network request to upload malicious code to the vulnerable installation and then trigger the execution of arbitrary system commands. According to the description, the flaw is essentially identical to CVE-2025-54948, but targeted at a different processor architecture.

Impact

An attacker can gain unauthorized access to the system, execute arbitrary commands in its context, and potentially take control of the Apex One management service, which threatens the confidentiality and availability of protected resources.

Mitigation & patch

Immediately apply patches available from the vendor in accordance with references published by Trend Micro at https://success.trendmicro.com/en-US/solution/KA-0020652. Until the fix is implemented, it is recommended to restrict network access to the Apex One management console to trusted IP addresses only and implement network-level firewall rules.

Who is affected

Trend Micro Apex One (on-premise version) – specific versions indicated in the vendor's references (https://success.trendmicro.com/en-US/solution/KA-0020652)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
  • Trendmicro Apex One

    APP
    Trendmicro
    2019
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2025-54948CRITICAL9.4⚠ KEVPL ✓same product

Command injection w Trend Micro Apex One – RCE bez uwierzytelnienia

CVE-2022-26871CRITICAL9.8⚠ KEVPL ✓same product

Trend Micro Apex Central — dowolne przesyłanie plików prowadzące do RCE

CVE-2020-8599CRITICAL9.8⚠ KEVPL ✓same product

Trend Micro Apex One / OfficeScan XG — zapis pliku bez uwierzytelnienia i bypass loginu ROOT

CVE-2023-32557CRITICAL9.8PL ✓same product

Path Traversal umożliwiający RCE w Trend Micro Apex One

CVE-2023-25143CRITICAL9.8PL ✓same product

RCE poprzez niekontrolowany element ścieżki wyszukiwania w instalatorze Trend Micro Apex One Server