PT-2025-31925 · Trend Micro · Trend Micro Apex One

Jacky Hsieh

·

Published

2025-08-01

·

Updated

2026-05-25

·

CVE-2025-54948

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro Apex One (on-premise) (affected versions not specified)
Description A vulnerability exists in the Trend Micro Apex One (on-premise) management console that could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. This issue is actively exploited in the wild. The vulnerability is related to command injection within the Management Console.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-10969
CVE-2025-54948
ZDI-25-771
ZDI-26-269

Affected Products

Trend Micro Apex One