CVE-2025-54948

9.5 CISA KEV

Trend Micro · Apex One

Trend Micro Apex One (on-premise) is vulnerable to OS command injection, allowing remote attackers to upload and execute arbitrary code on the management console.

Executive summary

A critical OS command injection vulnerability in Trend Micro Apex One is currently being actively exploited in the wild, posing an immediate risk of full system compromise.

Vulnerability

This flaw, categorized as CWE-78 (OS Command Injection), allows an unauthenticated remote attacker to inject and execute arbitrary system commands via the management console. The vulnerability stems from improper validation of input during file operations, which facilitates the execution of malicious code.

Business impact

The exploitation of this vulnerability results in full remote code execution, which grants attackers the ability to manipulate security configurations, exfiltrate sensitive data, or install persistent malware across the enterprise network. Given the CVSS score of 9.5 and confirmed active exploitation, this flaw represents a critical threat to organizational integrity and data privacy.

Remediation

Immediate Action: Update all instances of Trend Micro Apex One to version 14.0.0.14039 or later immediately as per the vendor security advisory.

Proactive Monitoring: Review management console access logs for unusual file upload activity or unexpected process execution patterns originating from the web interface.

Compensating Controls: Implement strict network access control lists to limit access to the Apex One management console to known, trusted administrative IP addresses until patching is complete.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical severity and confirmed status of this vulnerability in the CISA Known Exploited Vulnerabilities catalog, organizations must prioritize this update above all other routine maintenance. Failure to apply the vendor-provided patch leaves the management console exposed to trivial remote compromise. Verify that all affected installations are updated immediately to neutralize this active threat.

More Trend Micro CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief critical section
  4. Published in the daily brief kev section
  5. Published in the daily brief kev section
  6. Published in the daily brief kev section
  7. Published in the daily brief kev section
  8. Published in the daily brief kev section
  9. Published in the daily brief kev section
  10. Published in the daily brief kev section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief kev section
  16. Published in the daily brief kev section
  17. Published in the daily brief kev section
  18. Published in the daily brief kev section
  19. Published in the daily brief kev section
  20. Published in the daily brief kev section
  21. Published in the daily brief kev section
  22. Analyst report written
  23. Fix documented version 14.0.0.14039 per CVE record

Sources