CVE-2025-13447
largeAuthenticated OS Command Injection RCE in Progress LoadMaster API
CVE-2025-13447 is an OS command injection flaw (CWE-78) in the API of Progress LoadMaster, Progress's load-balancer/ADC appliance, where unsanitized API input parameters are passed to the underlying system. An attacker who is already authenticated and holds 'User Administration' permissions can send crafted API requests that cause arbitrary operating-system commands to be executed on the appliance, yielding full code execution with the appliance's confidentiality, integrity, and availability at stake (C:H/I:H/A:H). The adjacent-network, high-privilege prerequisites are reflected in the medium CVSS 3.1 score of 6.8. Affected parties are organizations running LoadMaster appliances, and the CPE mapping additionally ties the flaw to related Progress products that incorporate LoadMaster components: ECS Connection Manager, Connection Manager for ObjectScale, MOVEit WAF, and Multi-Tenant Hypervisor. There is currently no known public proof-of-concept, the flaw is not yet in CISA's KEV catalog, and no confirmed in-the-wild exploitation is documented, though EPSS assigns a high 25.3% probability of exploitation within 30 days.
What to do: Upgrade LoadMaster — and any deployed ECS Connection Manager, Connection Manager for ObjectScale, MOVEit WAF, or Multi-Tenant Hypervisor units — to the fixed releases listed in Progress's security advisory for CVE-2025-13447 (no fixed version numbers were provided in this data). Until patched, restrict access to the LoadMaster management API to trusted admin networks and audit which accounts hold 'User Administration' privileges, removing or downgrading any that do not need it. Watch Progress PSIRT communications, since the high EPSS score suggests exploitation may begin soon and bundled-product advisories may follow.
| Progress LoadMaster | — |
| Progress ECS Connection Manager | — |
| Progress Connection Manager for ObjectScale | — |
| Progress MOVEit WAF | — |
| Progress Multi-Tenant Hypervisor | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters
- Vendors
- progress
- Products
- connection manager for objectscale*, ecs connection manager, loadmaster, moveit waf, multi-tenant hypervisor
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.