CVE-2016-5840: Trend Micro Deep Discovery Inspector

High severity, CVSS 7.2. EPSS: 7.8% chance of exploitation in the next 30 days.

hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header.

Affected products

  • Trend Micro Deep Discovery Inspector: version 3.7 only; version 3.81 only; version 3.82 only

Published 2016-06-30. Last modified 2026-06-17.