ZDI-26-144: Trend Micro Apex Central Hub Server Server-Side Request Forgery Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Trend Micro Apex Central. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.4. The following CVEs are assigned: CVE-2025-71205.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-144?
ZDI-26-144 has a high severity rating due to its potential to disclose sensitive information.
How do I fix ZDI-26-144?
To fix ZDI-26-144, apply the latest security updates provided by Trend Micro for Apex Central.
Who is affected by ZDI-26-144?
Only installations of Trend Micro Apex Central that are accessible and have authentication enabled are affected by ZDI-26-144.
Can ZDI-26-144 be exploited without authentication?
No, exploitation of ZDI-26-144 requires valid authentication credentials to access the affected system.
What type of vulnerability is ZDI-26-144?
ZDI-26-144 is classified as a Server-Side Request Forgery (SSRF) vulnerability.