← Back

Threat Discovery Appliance

threat_discovery_appliance

Vendor: Trendmicro • 12 CVEs

CVEs (12)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via a .. (dot dot) in the dID parameter.
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
7.3 HIGH· v3
6.0 MEDIUM· v2
The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file.
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
7.3 HIGH· v3
6.0 MEDIUM· v2
dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via an archive file containing a symlink to /eng_ptn_stores/prod/sensorSD...Show more
dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via an archive file containing a symlink to /eng_ptn_stores/prod/sensorSDK/data/ or /eng_ptn_stores/prod/sensorSDK/backup_pol/.Show less
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id paramete...Show more
detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.Show less
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the timezone parameter.
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 28, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication by guessing the value.
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 12, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass au...Show more
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS.Show less
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 12, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface.