CVE-2025-71210
Summary
| CVE | CVE-2025-71210 |
|---|---|
| State | PUBLISHED |
| Assigner | trendmicro |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-21 14:16:43 UTC |
| Updated | 2026-05-21 15:05:28 UTC |
| Description | A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via a researcher through the Zero Day Initiative. The SaaS versions of the product have already been mitigated and no customer action required. For this particular vulnerability, an attacker must have access to the Trend Micro Apex One Management Console, so customers that have their console�s IP address exposed externally should consider mitigating factors such as source restrictions if not already applied. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.005520000 probability, percentile 0.682920000 (date 2026-05-28)
Problem Types: CWE-22 | CWE-22 CWE-22: Improper Limitation of a Pathname to a Restricted Directory
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Trend Micro Inc. | TrendAI Apex One | affected 2019 (14.0) 14.0.0.14136 semver | Not specified |
| CNA | Trend Micro Inc. | TrendAI Apex One As A Service | affected SaaS 14.0.20315 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| success.trendmicro.com/en-US/solution/KA-0022458 | [email protected] | success.trendmicro.com | |
| www.zerodayinitiative.com/advisories/ZDI-26-136 | [email protected] | www.zerodayinitiative.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.