OS Command Injection in Apex One - CVE-2025-54948

 

OS Command Injection in Apex One - CVE-2025-54948

Published: August 6, 2025 / Updated: August 6, 2025


Vulnerability identifier: #VU113667
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-54948
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation in management console. A remote unauthenticated attacker can upload malicious code and execute arbitrary commands on the affected system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Apex One

How to mitigate CVE-2025-54948

Deploy a temporary fix provided by the vendor.


External References

Related Security Bulletins