ZeroHour

CVE-2025-13444

moderate

Authenticated OS Command Injection RCE in Progress LoadMaster API

CVSS 3.1
6.8 medium
EPSS
25%p98
Published
()
Modified
AI analysis

CVE-2025-13444 is an OS command injection flaw (CWE-78) in the API of Progress LoadMaster, Progress's load balancer/application delivery appliance. An authenticated attacker holding 'User Administration' permissions can trigger it by supplying unsanitized input in API request parameters, causing the appliance to execute arbitrary operating-system commands. Successful exploitation gives full command execution on the appliance with high impact to confidentiality, integrity, and availability - enough to take over the load balancer, potentially observe or manipulate the traffic it handles, and pivot into the networks behind it; the CVSS 6.8 score reflects the mitigating requirements of an adjacent network position and high (admin-level) privileges. Organizations running Progress LoadMaster appliances or virtual load balancers are affected; specific affected and fixed version ranges were not included in the available data. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the 25.3% EPSS score (98th percentile) indicates a meaningful probability of exploitation within the next 30 days.

What to do: Upgrade LoadMaster to the patched release identified in Progress's advisory for CVE-2025-13444 (version numbers were not included in the available data, so check the advisory for exact fixed builds). Until patched, restrict access to the LoadMaster management UI and API to trusted management networks and review which accounts hold 'User Administration' permissions. Given the high EPSS score, monitor appliance logs for unexpected commands or API activity and prioritize applying the fix within days rather than weeks.

Affected
progress loadmaster
progress multi-tenant hypervisor
progress connection manager for objectscale
progress ecs connection manager
progress moveit web application firewall
Estimated exposure
moderatetens of thousands of deployed appliances (order of 10k-100k, including internet-exposed instances) — Progress LoadMaster (formerly Kemp) is a widely deployed application delivery appliance whose instances appear on public internet scans in the tens of thousands, and these appliances are commonly exposed to service published applications,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters

Vendors
progress
Products
connection manager for objectscale, ecs connection manager, moveit web application firewall, multi-tenant hypervisor, loadmaster
Weakness
CWE-78
Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.