Views:
 
This bulletin is provided as an INFORMTION ONLY BULLETIN – meaning that the issues outlined in this bulletin are historical and are for the purposes of researcher acknowledgement and CVE documentation. Both vulnerabilities in this bulletin were resolved by December 2025. No action is required from customers who regularly update the product via monthly maintenance.
 

Previously Impacted Product(s)
 

ProductPlatformLanguage
TrendAI Vision One Service Gateway SaaSEnglish



Vulnerability Details

CVE-2025-71386: Information Disclosure Vulnerability
ZDI-CAN-28148
CVSS:3.1 – 9.9 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) at time of initial report

An information disclosure vulnerability previously discovered in TrendAI Vision One Service Gateway could allow a remote attacker to access sensitive information.

Please note: the key part of this vulnerability was promptly addressed on the backend in September 2025 after it was reported which effectively mitigated the risk of the vulnerability, and remnant updates to the client side were deployed in September 2025 and October 2025 monthly maintenance service updates (depending on service region).


CVE-2025-71387: Incorrect Privilege Assignment Privilege Escalation Vulnerability
ZDI-CAN-28122
CVSS:3.1 – 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) at time of initial report

A privilege escalation vulnerability previously discovered in TrendAI Vision One Service Gateway could allow a user with certain key roles to elevate their privileges.

Please note: this vulnerability was addressed and deployed in the December 2025 monthly maintenance service update (depending on service region).


Acknowledgement

TrendAI would like to thank the following individuals and/or organizations for responsibility disclosing these issues and working with us to help protect our customers:

  • Hugo LECLERCQ working with TrendAI Zero Day Initiative (CVE-2025-71386)
  • Xavier DANEST - Decathlon working with TrendAI Zero Day Initiative (CVE-2025-71387)