CVE Explorer
CVE-2025-71210
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations.
Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via a researcher through the Zero Day Initiative. The SaaS versions of the product have already been mitigated and no customer action required.
For this particular vulnerability, an attacker must have
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 2 assertions
{"cpes":["cpe:2.3:a:trendmicro:apexone_op:14.0.0.14136:*:*:*:*:*:*:*"],"product":"TrendAI Apex One","vendor":"Trend Micro, Inc.","versions":[{"lessThan":"14.0.0.14136","status":"affected","version":"2019 (14.0)","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:789f0ab2033ee5251ab0ab9e3160c37fa7c088e8a65eeca766872e982e7616e0 · sha256:30c39e0590eb25f7… · /containers/cna/affected/0
{"cpes":["cpe:2.3:a:trendmicro:apexone_saas:14.0.0.20315:*:*:*:*:*:*:*"],"product":"TrendAI Apex One as a Service","vendor":"Trend Micro, Inc.","versions":[{"lessThan":"14.0.20315","status":"affected","version":"SaaS","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:789f0ab2033ee5251ab0ab9e3160c37fa7c088e8a65eeca766872e982e7616e0 · sha256:30c39e0590eb25f7… · /containers/cna/affected/1
Affected products and versions
2 source assertions{"cpes":["cpe:2.3:a:trendmicro:apexone_op:14.0.0.14136:*:*:*:*:*:*:*"],"product":"TrendAI Apex One","vendor":"Trend Micro, Inc.","versions":[{"lessThan":"14.0.0.14136","status":"affected","version":"2019 (14.0)","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:789f0ab2033ee5251ab0ab9e3160c37fa7c088e8a65eeca766872e982e7616e0 · sha256:30c39e0590eb25f7… · /containers/cna/affected/0
{"cpes":["cpe:2.3:a:trendmicro:apexone_saas:14.0.0.20315:*:*:*:*:*:*:*"],"product":"TrendAI Apex One as a Service","vendor":"Trend Micro, Inc.","versions":[{"lessThan":"14.0.20315","status":"affected","version":"SaaS","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:789f0ab2033ee5251ab0ab9e3160c37fa7c088e8a65eeca766872e982e7616e0 · sha256:30c39e0590eb25f7… · /containers/cna/affected/1
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:789f0ab2033ee5251ab0ab9e3160c37fa7c088e8a65eeca766872e982e7616e0 · sha256:30c39e0590eb25f7… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory","lang":"en-US","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:789f0ab2033ee5251ab0ab9e3160c37fa7c088e8a65eeca766872e982e7616e0 · sha256:30c39e0590eb25f7… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://success.trendmicro.com/en-US/solution/KA-0022458"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:789f0ab2033ee5251ab0ab9e3160c37fa7c088e8a65eeca766872e982e7616e0 · sha256:30c39e0590eb25f7… · /containers/cna/references/0
{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-136/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:789f0ab2033ee5251ab0ab9e3160c37fa7c088e8a65eeca766872e982e7616e0 · sha256:30c39e0590eb25f7… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.