A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the adminsystime.cgi interface.
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a sessionid cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS.