Vulnerability record · CVE-2020-28580 · published 18 November 2020
CVE-2020-28580: Trend Micro InterScan Web Security Virtual Appliance command injection in AddVLANItem
Trendmicro · Interscan Web Security Virtual Appliance
AddVLANItem in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 fails to neutralize input in HTTP messages, allowing OS command injection (CWE-78). An authenticated remote attacker can send crafted requests to run arbitrary commands with elevated privileges on the appliance.
Description
A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote command execution with elevated privileges on a security appliance, with public exploit material and very high EPSS, though it requires authenticated access.
What it is
AddVLANItem in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 fails to neutralize input in HTTP messages, allowing OS command injection (CWE-78). An authenticated remote attacker can send crafted requests to run arbitrary commands with elevated privileges on the appliance.
Impact
The attacker executes arbitrary OS commands with elevated privileges, giving full control of the security appliance and its traffic inspection role. This can lead to data exposure, configuration tampering and use of the appliance as a pivot into the network.
Attack surface
Reached over the network via specially crafted HTTP messages to the AddVLANItem function; the CVSS vector (AV:N/AC:L/PR:H/UI:N) indicates no user interaction but high privileges, so a valid administrative-level account is required.
Exploitation
Not listed in CISA KEV and no ransomware usage documented, but EPSS is 0.44953 (98.7th percentile) and a Tenable reference is tagged Exploit, indicating public exploit material exists.
What to do
- Apply the vendor fix from Trend Micro solution 000281954 for InterScan Web Security Virtual Appliance 6.5 SP2.
- Restrict management interface access to trusted administrative networks and disable it from untrusted segments.
- Enforce least privilege and strong unique credentials for appliance administrators; audit accounts with elevated rights.
- Monitor and alert on unexpected outbound connections or process execution on the appliance.
- If patching is delayed, isolate the appliance and review logs for anomalous AddVLANItem requests.
Detection
- Inspect HTTP request logs for AddVLANItem calls containing shell metacharacters or unexpected parameters.
- Alert on new or unusual child processes spawned by the web/appliance service.
- Monitor for outbound network connections from the appliance to unknown hosts.
- Correlate administrative logins with subsequent command execution or configuration changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://success.trendmicro.com/solution/000281954 | Vendor Advisory |
| https://www.tenable.com/security/research/tra-2020-63 | ExploitThird Party Advisory |
| https://success.trendmicro.com/solution/000281954 | Vendor Advisory |
| https://www.tenable.com/security/research/tra-2020-63 | ExploitThird Party Advisory |
Track CVE-2020-28580 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-28580), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.