CVE-2025-54948 is a critical OS command injection vulnerability in Trend Micro Apex One on-premise management console that allows pre-authenticated remote attackers to upload malicious code and execute arbitrary commands. CISA has added this vulnerability to the KEV catalog due to active exploitation in the wild.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-08-05
Added to CISA KEV: 2025-08-18 13 DAYS BETWEEN CVE AND KEV
This vulnerability is essentially the same as CVE-2025-54948 but targets a different CPU architecture. Mitigating Factors. Exploiting these type of ...
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code ...
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
The vulnerability, tracked as CVE-2025-54948 and classified under CWE-78, poses significant risks to organizations running on-premise installations of the enterprise security platform. Key Takeaways 1. CISA confirms CVE-2025-54948 attacks on Trend Micro Apex One.
Both stem from a command injection issue that allows unauthenticated, remote threat actors to execute arbitrary code on vulnerable systems.