CVE-2025-54948
CVSS Score
9.4
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.
| Vendor | trend micro, inc. |
| Product | trend micro apex one |
| Published | Aug 5, 2025 |
| Last Updated | Oct 21, 2025 |
โ ๏ธ Actively Exploited โ Act Now
Get instant alerts for trend micro, inc. trend micro apex one
This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2025-54948.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
High
Affected Versions
Trend Micro, Inc. / Trend Micro Apex One
2019 (14.0) < 14.0.0.14039