Vulnerability record · CVE-2016-7552 · published 12 April 2017
CVE-2016-7552: Trend Micro Threat Discovery Appliance path traversal in session_id cookie
Trendmicro · Threat Discovery Appliance
The Trend Micro Threat Discovery Appliance 2.6.1062r1 processes the session_id cookie without sanitizing path traversal sequences, allowing a remote, unauthenticated attacker to delete arbitrary files as root. Because deletion runs with root privileges, the flaw can be used to bypass authentication or cause a denial of service.
Description
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, root-level file deletion, and public exploit code make this a critical risk.
What it is
The Trend Micro Threat Discovery Appliance 2.6.1062r1 processes the session_id cookie without sanitizing path traversal sequences, allowing a remote, unauthenticated attacker to delete arbitrary files as root. Because deletion runs with root privileges, the flaw can be used to bypass authentication or cause a denial of service.
Impact
An attacker can delete arbitrary files as root on the appliance, which can remove authentication-related files to bypass login or destroy system files to cause a denial of service.
Attack surface
Reachable over the network via a crafted session_id cookie; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.93249, 99.8th percentile) and references include an Exploit-tagged Metasploit commit, indicating public exploit code exists.
What to do
- Apply the vendor patch or fixed firmware for Threat Discovery Appliance 2.6.1062r1 if available.
- If no patch exists, isolate the appliance from untrusted networks and restrict management access to trusted hosts.
- Validate and reject session_id cookie values containing path traversal sequences at any proxy or WAF in front of the appliance.
- Back up the appliance configuration and monitor for unexpected file deletions or authentication failures.
- Retire or replace the appliance if it is end-of-support and cannot be patched.
Detection
- Monitor appliance and web logs for session_id cookie values containing ../ or encoded traversal sequences.
- Alert on unexpected deletion or disappearance of system or authentication files on the appliance.
- Watch for authentication bypass attempts or repeated login failures against the appliance.
- Use file integrity monitoring on the appliance filesystem to detect unauthorized deletions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/97599 | Third Party AdvisoryVDB Entry |
| https://github.com/rapid7/metasploit-framework/pull/8216/commits/0f07875a2ddb0bfbb4e985ab074e9fc56da1dcf6 | ExploitThird Party Advisory |
| http://www.securityfocus.com/bid/97599 | Third Party AdvisoryVDB Entry |
| https://github.com/rapid7/metasploit-framework/pull/8216/commits/0f07875a2ddb0bfbb4e985ab074e9fc56da1dcf6 | ExploitThird Party Advisory |
Track CVE-2016-7552 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-7552), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.