← Vulnerability feed

Vulnerability record · CVE-2016-7552 · published 12 April 2017

CVE-2016-7552: Trend Micro Threat Discovery Appliance path traversal in session_id cookie

Trendmicro · Threat Discovery Appliance

The Trend Micro Threat Discovery Appliance 2.6.1062r1 processes the session_id cookie without sanitizing path traversal sequences, allowing a remote, unauthenticated attacker to delete arbitrary files as root. Because deletion runs with root privileges, the flaw can be used to bypass authentication or cause a denial of service.

9.8 CVSS 3.0 Critical EPSS 93% · top 0.2% CWE-22 · Path traversal
9.8CVSS 3.0 base score, v2 10.0
93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, root-level file deletion, and public exploit code make this a critical risk.

What it is

The Trend Micro Threat Discovery Appliance 2.6.1062r1 processes the session_id cookie without sanitizing path traversal sequences, allowing a remote, unauthenticated attacker to delete arbitrary files as root. Because deletion runs with root privileges, the flaw can be used to bypass authentication or cause a denial of service.

Impact

An attacker can delete arbitrary files as root on the appliance, which can remove authentication-related files to bypass login or destroy system files to cause a denial of service.

Attack surface

Reachable over the network via a crafted session_id cookie; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.93249, 99.8th percentile) and references include an Exploit-tagged Metasploit commit, indicating public exploit code exists.

What to do

  • Apply the vendor patch or fixed firmware for Threat Discovery Appliance 2.6.1062r1 if available.
  • If no patch exists, isolate the appliance from untrusted networks and restrict management access to trusted hosts.
  • Validate and reject session_id cookie values containing path traversal sequences at any proxy or WAF in front of the appliance.
  • Back up the appliance configuration and monitor for unexpected file deletions or authentication failures.
  • Retire or replace the appliance if it is end-of-support and cannot be patched.

Detection

  • Monitor appliance and web logs for session_id cookie values containing ../ or encoded traversal sequences.
  • Alert on unexpected deletion or disappearance of system or authentication files on the appliance.
  • Watch for authentication bypass attempts or repeated login failures against the appliance.
  • Use file integrity monitoring on the appliance filesystem to detect unauthorized deletions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-7552 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-8584Trendmicro threat discovery appliance improper access control vulnerabilityTrend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication…EPSS 5.6%9.8CVE-2016-7547Trend Micro Threat Discovery Appliance timezone parameter command executionThe admin_sys_time.cgi interface in Trend Micro Threat Discovery Appliance 2.6.1062r1 fails to properly handle the timezone parameter, allowing comma…EPSS 93%analysed8.8CVE-2016-8585Trendmicro threat discovery appliance permissions and access controls vulnerabilityadmin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as th…EPSS 7.2%8.8CVE-2016-8586Trendmicro threat discovery appliance permissions and access controls vulnerabilitydetected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary …EPSS 6.1%8.8CVE-2016-8589Trendmicro threat discovery appliance permissions and access controls vulnerabilitylog_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the…EPSS 5.7%8.8CVE-2016-8590Trendmicro threat discovery appliance permissions and access controls vulnerabilitylog_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the…EPSS 5.7%8.8CVE-2016-8591Trendmicro threat discovery appliance permissions and access controls vulnerabilitylog_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the roo…EPSS 6.2%8.8CVE-2016-8592Trendmicro threat discovery appliance permissions and access controls vulnerabilitylog_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as …EPSS 6.2%

Source: NIST National Vulnerability Database (record CVE-2016-7552), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.