Skip to content
COOEY

EXPOSURES › CVE-2025-54948

CVE-2025-54948

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-08-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-54948 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Trend Micro Apex One suffered OS command injection, allowing remote attackers to upload and execute malicious code pre-authenticatedly.

Trend Micro Apex One Management Console (on-premise) had an OS command injection vulnerability that enabled remote attackers to upload and execute malicious code, pre-authenticatedly.

Shame score — Active exploitation of a critical pre-authenticated vulnerability in a widely-used product.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Trend Micro Cloud One for Government
Trend Micro Inc.
In Process
Trend Micro Vision One for Government
Trend Micro Inc.
In Process