EXPOSURES › CVE-2025-54948
CVE-2025-54948
HIGH ⌖ ON CISA KEV · EXPLOITEDTrend Micro Apex One suffered OS command injection, allowing remote attackers to upload and execute malicious code pre-authenticatedly.
Trend Micro Apex One Management Console (on-premise) had an OS command injection vulnerability that enabled remote attackers to upload and execute malicious code, pre-authenticatedly.
Shame score — Active exploitation of a critical pre-authenticated vulnerability in a widely-used product.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.
| PRODUCT | STATUS |
|---|---|
| Trend Micro Cloud One for Government Trend Micro Inc. |
In Process |
| Trend Micro Vision One for Government Trend Micro Inc. |
In Process |