LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-54948: Trend Micro Apex One OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 18, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 8, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-54948 to its Known Exploited Vulnerabilities catalog on Aug 18, 2025, with a federal patch deadline of Sep 8, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands…

CVE-2025-54948 is an OS command injection vulnerability in the on-premise Trend Micro Apex One Management Console. A pre-authenticated remote attacker could upload malicious code and execute commands on affected installations. This matters because the management console typically holds elevated privileges over endpoint security agents; successful abuse can give an attacker a foothold for further lateral movement or control of protected systems. Confirm all product-specific details against the vendor advisory.

How it works

The flaw is classified as CWE-78 (OS Command Injection). In products of this class, user-supplied input reaches an operating-system command interpreter without sufficient sanitization or parameterization. An attacker who can reach the vulnerable interface can craft input that causes the console process to run arbitrary commands under the privileges of the Apex One service account. The CISA summary states that the attack can be performed pre-authentication and can include uploading malicious code that is then executed. Exact request formats, parameters, or payloads are not provided here; treat any public proof-of-concept material with caution and validate behavior only in isolated lab environments against the vendor’s technical description.

Am I affected? How to find it in your systems

Trend Micro Apex One is commonly deployed as an on-premise management server that communicates with endpoint agents across Windows and mixed environments. Inventory steps:

How to remediate

Apply the vendor-supplied update or mitigation package for CVE-2025-54948 as the primary action. Follow the exact installation and verification steps published by Trend Micro. After patching:

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These steps lower risk but do not eliminate the underlying command-injection condition; schedule the official patch as soon as operationally feasible.

If your data may have been exposed

Command-injection flaws of this class can lead to full compromise of the management server and, by extension, the endpoints it controls. While ransomware use of this specific CVE is not documented, any successful exploitation should be treated as a potential breach. Review console and endpoint logs for indicators of unauthorized activity, isolate affected hosts, and follow your incident-response plan. Separately, individuals can run a free exposure scan of their email addresses against known breach data sets to determine whether personal credentials have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTrend Micro · Apex One
WeaknessCWE-78
Added to CISA KEVAug 18, 2025
Federal patch deadlineSep 8, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities