Junglewise Threat Intelligence

CVE-2025-54948: Trend Micro Apex One OS command injection in management console

CVE-2025-54948 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-08-18

Technologies: Trend Micro Apex One as a Service, Trend Micro Apex One. Vendors: Trend Micro, Trend Micro.

Executive brief

Trend Micro Apex One is a centralized security management platform used by organizations to protect endpoints from malware and other threats. A critical vulnerability in its management console allows an unauthorized attacker to remotely upload and run malicious code on the server. This could lead to a complete takeover of the security management system, potentially compromising the entire network of protected devices.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Trend Micro Apex One (on-premise) management console. The flaw allows a remote, unauthenticated attacker to bypass security controls to upload malicious files and execute arbitrary commands with elevated privileges on the underlying operating system. The attack vector is network-based and requires no user interaction or prior authentication. This vulnerability has been observed being exploited in the wild. Trend Micro has released a patch to address this issue, and users are advised to apply it immediately.

Affected products

  • Trend Micro Apex One (on-premise) management console 2019

Timeline

  • 2025-08-05: disclosed: Initial disclosure by Trend Micro
  • 2025-08-05: patched: Vendor advisory and patch released
  • 2025-08-18: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-08-18: exploited: Confirmed active exploitation in the wild

Related threats