{"document":{"category":"csaf_vex","csaf_version":"2.0","notes":[{"category":"summary","text":"ITW CRITICAL SECURITY BULLETIN: Trend Micro Apex One (On-Premise) Management Console Command Injection RCE Vulnerabilities","title":"Title"}],"publisher":{"category":"vendor","contact_details":"security@trendmicro.com","issuing_authority":"Trend Micro PSIRT","name":"Trend Micro","namespace":"https://www.trendmicro.com/vulnerability"},"references":[{"category":"self","summary":"Trend Micro Security Bulletin","url":"https://success.trendmicro.com/en-US/solution/KA-0020652"}],"title":"ITW CRITICAL SECURITY BULLETIN: Trend Micro Apex One (On-Premise) Management Console Command Injection RCE Vulnerabilities","tracking":{"current_release_date":"2025-08-05T10:00:00.000Z","generator":{"date":"2025-09-05T14:25:10.649Z","engine":{"name":"Secvisogram","version":"2.5.34"}},"id":"2025-0805-TM-A1-002","initial_release_date":"2025-08-05T10:00:00.000Z","revision_history":[{"date":"2025-08-05T10:00:00.000Z","number":"1","summary":"Initial version."},{"date":"2025-08-15T19:00:00.000Z","number":"2","summary":"Updated solution"}],"status":"final","version":"2"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_version","name":"2019","product":{"name":"Apex One","product_id":"TM-A1-001"}}],"category":"product_name","name":"Apex One"},{"branches":[{"category":"product_version","name":"SaaS","product":{"name":"Apex One as a Service","product_id":"TM-A1SAAS-001"}}],"category":"product_name","name":"Apex One as a Service"}],"category":"vendor","name":"Trend Micro"}]},"vulnerabilities":[{"acknowledgments":[{"names":["Trend Micro Incident Response (IR) Team","Jacky Hsieh @ CoreCloud Tech working with Trend Zero Day Initiative"]}],"cve":"CVE-2025-54948","cwe":{"id":"CWE-78","name":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"},"notes":[{"category":"description","text":"A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.","title":"CVE description"}],"product_status":{"fixed":["TM-A1SAAS-001"],"known_affected":["TM-A1-001"]},"references":[{"category":"external","summary":"ZDI-CAN-27834","url":"https://www.zerodayinitiative.com/advisories/published/"}],"remediations":[{"category":"vendor_fix","date":"2025-08-05T19:00:00.000Z","details":"FixTool_Aug2025","product_ids":["TM-A1-001"],"url":"https://success.trendmicro.com/en-US/solution/KA-0020652"},{"category":"vendor_fix","date":"2025-07-31T19:00:00.000Z","details":"Backend Mitigation Applied","product_ids":["TM-A1SAAS-001"],"url":"https://success.trendmicro.com/en-US/solution/KA-0020652"},{"category":"vendor_fix","date":"2025-08-15T19:00:00.000Z","details":"SP1 CP B14081","product_ids":["TM-A1-001"],"url":"https://success.trendmicro.com/en-US/solution/KA-0020652"}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.4,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","environmentalScore":9.4,"environmentalSeverity":"CRITICAL","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":9.4,"temporalSeverity":"CRITICAL","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H","version":"3.1"},"products":["TM-A1-001","TM-A1SAAS-001"]}],"title":"Management Console Command Injection RCE Vulnerability"},{"acknowledgments":[{"names":["Jacky Hsieh @ CoreCloud Tech working with Trend Zero Day Initiative"]}],"cve":"CVE-2025-54987","cwe":{"id":"CWE-78","name":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"},"notes":[{"category":"description","text":"A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is essentially the same as CVE-2025-54948 but targets a different CPU architecture.","title":"CVE description"}],"product_status":{"fixed":["TM-A1SAAS-001"],"known_affected":["TM-A1-001"]},"references":[{"category":"external","summary":"ZDI-CAN-27855","url":"https://www.zerodayinitiative.com/advisories/published/"}],"remediations":[{"category":"vendor_fix","date":"2025-08-05T19:00:00.000Z","details":"FixTool_Aug2025","product_ids":["TM-A1-001"],"url":"https://success.trendmicro.com/en-US/solution/KA-0020652"},{"category":"vendor_fix","date":"2025-07-31T19:00:00.000Z","details":"Backend Mitigation Applied","product_ids":["TM-A1SAAS-001"],"url":"https://success.trendmicro.com/en-US/solution/KA-0020652"},{"category":"vendor_fix","date":"2025-08-15T19:00:00.000Z","details":"SP1 CP B14081","product_ids":["TM-A1-001"],"url":"https://success.trendmicro.com/en-US/solution/KA-0020652"}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.4,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","environmentalScore":9.4,"environmentalSeverity":"CRITICAL","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":9.4,"temporalSeverity":"CRITICAL","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H","version":"3.1"},"products":["TM-A1-001","TM-A1SAAS-001"]}],"title":"Management Console Command Injection RCE Vulnerability"}]}