← All Advisories

Trend Micro Apex One Management Console Path Traversal in a Second Executable Allows Remote Attackers to Upload Malicious Code and Execute Commands on Affected Installations

Last refreshed2026-09-28

Status: UPDATED  |  Advisory ID: CVE-2025-71211

Key Details

CVECVE-2025-71211
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-07-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productstrendmicro apex_one
Classified asCWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
trendmicroapex_one
SubsystemsGeneral OT
SectorsMultiple

What to Know

A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is similar in scope to CVE-2025-71210 but affects a different executable.

Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via a researcher through the Zero Day Initiative. The SaaS versions of the product have already been mitigated and no customer action required.

For this particular vulnerability, an attacker must have access to the Trend Micro Apex One Management Console, so customers that have their console�s IP address exposed externally should consider mitigating factors such as source restrictions if not already applied. (NVD)

What to Do

Monitor trendmicro's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-71211
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-71211
Vendor advisoryhttps://success.trendmicro.com/en-US/solution/KA-0022458