← Vulnerability feed

Vulnerability record · CVE-2020-28580 · published 18 November 2020

CVE-2020-28580: Trend Micro InterScan Web Security Virtual Appliance command injection in AddVLANItem

Trendmicro · Interscan Web Security Virtual Appliance

AddVLANItem in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 fails to neutralize input in HTTP messages, allowing OS command injection (CWE-78). An authenticated remote attacker can send crafted requests to run arbitrary commands with elevated privileges on the appliance.

7.2 CVSS 3.1 High EPSS 45% · top 1.3% CWE-78 · OS command injection
7.2CVSS 3.1 base score, v2 9.0
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityRemote command execution with elevated privileges on a security appliance, with public exploit material and very high EPSS, though it requires authenticated access.

What it is

AddVLANItem in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 fails to neutralize input in HTTP messages, allowing OS command injection (CWE-78). An authenticated remote attacker can send crafted requests to run arbitrary commands with elevated privileges on the appliance.

Impact

The attacker executes arbitrary OS commands with elevated privileges, giving full control of the security appliance and its traffic inspection role. This can lead to data exposure, configuration tampering and use of the appliance as a pivot into the network.

Attack surface

Reached over the network via specially crafted HTTP messages to the AddVLANItem function; the CVSS vector (AV:N/AC:L/PR:H/UI:N) indicates no user interaction but high privileges, so a valid administrative-level account is required.

Exploitation

Not listed in CISA KEV and no ransomware usage documented, but EPSS is 0.44953 (98.7th percentile) and a Tenable reference is tagged Exploit, indicating public exploit material exists.

What to do

  • Apply the vendor fix from Trend Micro solution 000281954 for InterScan Web Security Virtual Appliance 6.5 SP2.
  • Restrict management interface access to trusted administrative networks and disable it from untrusted segments.
  • Enforce least privilege and strong unique credentials for appliance administrators; audit accounts with elevated rights.
  • Monitor and alert on unexpected outbound connections or process execution on the appliance.
  • If patching is delayed, isolate the appliance and review logs for anomalous AddVLANItem requests.

Detection

  • Inspect HTTP request logs for AddVLANItem calls containing shell metacharacters or unexpected parameters.
  • Alert on new or unusual child processes spawned by the web/appliance service.
  • Monitor for outbound network connections from the appliance to unknown hosts.
  • Correlate administrative logins with subsequent command execution or configuration changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-28580 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2016-9269Trendmicro interscan web security virtual appliance permissions and access controls vulnerabilityRemote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_…EPSS 13%9.8CVE-2020-8465Trendmicro interscan web security virtual appliance improper authentication vulnerabilityA vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combinat…EPSS 2.7%9.8CVE-2020-8466Trend Micro InterScan Web Security Virtual Appliance command injection via passwordTrend Micro InterScan Web Security Virtual Appliance 6.5 SP2 with improved password hashing enabled contains an OS command injection flaw (CWE-78). A…EPSS 64%analysed9.8CVE-2020-28578Trend Micro InterScan Web Security Virtual Appliance out-of-bounds write RCETrend Micro InterScan Web Security Virtual Appliance 6.5 SP2 contains an out-of-bounds write (CWE-787) reachable through a specially crafted HTTP mes…EPSS 73%analysed9.8CVE-2020-8606Trend Micro InterScan Web Security Virtual Appliance authentication bypassTrend Micro InterScan Web Security Virtual Appliance 6.5 contains an improper authentication flaw (CWE-287) that lets remote attackers bypass authent…EPSS 73%analysed8.8CVE-2020-8461Trendmicro interscan web security virtual appliance cross-site request forgery vulnerabilityA CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's brow…EPSS 1.2%8.8CVE-2020-28579Trend Micro InterScan Web Security Virtual Appliance out-of-bounds write RCETrend Micro InterScan Web Security Virtual Appliance 6.5 SP2 contains an out-of-bounds write (CWE-787) reachable through a specially crafted HTTP mes…EPSS 51%analysed8.8CVE-2020-8605Trend Micro InterScan Web Security Virtual Appliance OS command injection RCETrend Micro InterScan Web Security Virtual Appliance 6.5 contains an OS command injection flaw (CWE-78) that lets a remote attacker run arbitrary cod…EPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2020-28580), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.