ZeroHour

CVE-2025-54948

KEVlarge

Pre-auth OS command injection in Trend Micro Apex One on-prem Management Console

CISA: Trend Micro Apex One OS Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
22%p98
Published
()
KEV added
AI analysis

Trend Micro Apex One's on-premises Management Console contains an OS command injection flaw (CWE-78) that a remote attacker can reach prior to authentication. By sending crafted requests to the console, the attacker can inject arbitrary OS commands and upload malicious code to the server hosting the console. Successful exploitation yields remote code execution on the Apex One management server, which typically holds privileged network access and controls the managed endpoint fleet. Only organizations running the on-premise Apex One Management Console are affected; the source data does not enumerate specific vulnerable builds. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-18, confirming active exploitation in the wild, though no public proof-of-concept is known and ransomware involvement is not yet confirmed.

What to do: Apply Trend Micro's patched builds or vendor-directed mitigations for the on-prem Apex One Management Console immediately, per the CISA KEV required action and BOD 22-01 guidance (federal agencies face a KEV deadline). Restrict the Management Console from direct internet exposure via firewall or VPN, and hunt the management server for signs of compromise such as unexpected uploaded files or processes, since active exploitation is confirmed. Ransomware association is unconfirmed but should be assumed possible until vendor guidance says otherwise.

Affected
Trend Micro Apex One (on-premises Management Console)
Estimated exposure
large≈ tens of thousands of on-prem Management Console deployments (estimate; no published install counts in source data) — Apex One is a widely deployed enterprise endpoint platform whose on-prem console is typically installed once per customer site, and only a subset of those consoles is internet-exposed, implying a low tens-of-thousands installed base rather…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.

CISA Known Exploited Vulnerability
Affected
Trend Micro Apex One
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
trendmicro
Products
apex one
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news