VYPR
Critical severity9.4CISA KEVNVD Advisory· Published Aug 5, 2025· Updated Jun 17, 2026

CVE-2025-54948

CVE-2025-54948

Description

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:on-premises:windows:*:*+ 1 more
    • cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:on-premises:windows:*:*
    • (no CPE)
  • Trend Micro, Inc./Trend Micro Apex Onev5
    cpe:2.3:a:trendmicro:apexone_server:14.0.0.14039:*:*:*:*:*:*:*
    Range: 2019 (14.0)

Patches

Vulnerability mechanics

References

2

News mentions

2