ZeroHour

CVE-2025-13447

large

Authenticated OS Command Injection RCE in Progress LoadMaster API

CVSS 3.1
6.8 medium
EPSS
25%p98
Published
()
Modified
AI analysis

CVE-2025-13447 is an OS command injection flaw (CWE-78) in the API of Progress LoadMaster, Progress's load-balancer/ADC appliance, where unsanitized API input parameters are passed to the underlying system. An attacker who is already authenticated and holds 'User Administration' permissions can send crafted API requests that cause arbitrary operating-system commands to be executed on the appliance, yielding full code execution with the appliance's confidentiality, integrity, and availability at stake (C:H/I:H/A:H). The adjacent-network, high-privilege prerequisites are reflected in the medium CVSS 3.1 score of 6.8. Affected parties are organizations running LoadMaster appliances, and the CPE mapping additionally ties the flaw to related Progress products that incorporate LoadMaster components: ECS Connection Manager, Connection Manager for ObjectScale, MOVEit WAF, and Multi-Tenant Hypervisor. There is currently no known public proof-of-concept, the flaw is not yet in CISA's KEV catalog, and no confirmed in-the-wild exploitation is documented, though EPSS assigns a high 25.3% probability of exploitation within 30 days.

What to do: Upgrade LoadMaster — and any deployed ECS Connection Manager, Connection Manager for ObjectScale, MOVEit WAF, or Multi-Tenant Hypervisor units — to the fixed releases listed in Progress's security advisory for CVE-2025-13447 (no fixed version numbers were provided in this data). Until patched, restrict access to the LoadMaster management API to trusted admin networks and audit which accounts hold 'User Administration' privileges, removing or downgrading any that do not need it. Watch Progress PSIRT communications, since the high EPSS score suggests exploitation may begin soon and bundled-product advisories may follow.

Affected
Progress LoadMaster
Progress ECS Connection Manager
Progress Connection Manager for ObjectScale
Progress MOVEit WAF
Progress Multi-Tenant Hypervisor
Estimated exposure
largeplausibly tens of thousands of deployed LoadMaster appliances (internet-exposed management/API interfaces likely in the thousands); exact count unknown — LoadMaster (formerly Kemp, acquired by Progress) is a long-standing enterprise load balancer historically marketed to tens of thousands of customers, and public internet scans routinely show thousands of exposed LoadMaster admin/API…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters

Vendors
progress
Products
connection manager for objectscale*, ecs connection manager, loadmaster, moveit waf, multi-tenant hypervisor
Weakness
CWE-78
Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.