CVE-2016-7552: Trend Micro Threat Discovery Appliance

Critical severity, CVSS 9.8. EPSS: 93.2% chance of exploitation in the next 30 days.

On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS.

Affected products

  • Trend Micro Threat Discovery Appliance: version 2.6.1062 only

Published 2017-04-12. Last modified 2026-06-17.