CVE-2016-7547 is a critical command execution vulnerability affecting Trend Micro Threat Discovery Appliance version 2.6.1062r1. This flaw allows unauthenticated attackers to execute arbitrary commands remotely via the timezone parameter in the admin_sys_time.cgi interface, leading to complete compromise of the appliance. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a severe risk. Exploit code is publicly available through a Metasploit module, and while not on the KEV catalog, it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.1062CPE matchmatch criteria | cpe:2.3:a:trendmicro:threat_discovery_appliance:2.6.1062:r1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.