CVE-2025-54948 – Remote Command Injection – Trend Micro Apex One Management Console

ISGroup Cybersecurity

Trend Micro Apex One (on-premise) Management Console is a centralized platform used by organizations to manage endpoint security policies, updates, and monitoring.
CVE-2025-54948 is an unauthenticated remote command injection vulnerability in the Apex One Management Console. A network-based attacker can execute arbitrary operating system commands without authentication by sending specially crafted requests.
The vulnerability affects Apex One Management Server version 14039 and earlier (on-premise) and is being actively exploited in real-world environments.

Date2025-08-13 10:31:03
Information
  • Active Exploitation

Technical Summary

The vulnerability is caused by insufficient validation of user-supplied input in a web-exposed component of the Apex One Management Console.
By crafting a malicious HTTP request, an unauthenticated attacker can inject system commands that the server executes with the privileges of the web application process, potentially leading to a full compromise of the management server.

This vulnerability can be exploited remotely over the network, without authentication and without user interaction.

Since the Apex One Management Console is typically connected to numerous managed endpoints, a successful attack can provide attackers with an entry point to deploy malicious payloads or reconfigure security policies on devices across the entire organization.
CVE-2025-54948 is closely related to CVE-2025-54987, which targets the same vulnerability on a different CPU architecture.

Recommendations

  1. Apply Temporary Mitigation: Immediately deploy the mitigation tool provided by Trend Micro in their advisory.
  2. Plan for Full Update: Update to the patched version as soon as it becomes available (expected mid-August 2025).
  3. Restrict Network Access: Limit access to the Apex One Management Console interface to trusted networks or VPN connections.
  4. Monitor Logs: Check server and web logs for suspicious requests that may indicate exploitation attempts.
  5. Isolate and Investigate: If exploitation is suspected, isolate the affected server and perform a forensic analysis before returning it to production.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert