CVE-2025-13444

8.4

Progress Software · LoadMaster

An OS command injection vulnerability in Progress LoadMaster allows an authenticated user with administrative permissions to execute arbitrary system commands via unsanitized API input.

Executive summary

Progress LoadMaster contains a critical OS command injection vulnerability that permits authenticated attackers with administrative privileges to achieve remote code execution on the appliance.

Vulnerability

The vulnerability is an OS command injection flaw (CWE-78) located within the API input parameters of the LoadMaster appliance. It requires the attacker to have an existing authenticated session with User Administration capabilities to successfully execute arbitrary commands.

Business impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands with the privileges of the underlying service, leading to full system compromise. Given the CVSS score of 8.4, this represents a high risk to organizational security, potentially resulting in data exfiltration, service disruption, or lateral movement within the network.

Remediation

Immediate Action: Review the official Progress Software community security advisories provided in the references to identify and apply the necessary firmware updates or configuration changes for your specific LoadMaster version.

Proactive Monitoring: Monitor system access logs for unauthorized API calls or unusual command execution patterns originating from administrative user accounts.

Compensating Controls: Restrict access to the management API to trusted administrative subnets and implement strict network segmentation to limit the potential blast radius of a compromised appliance.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability, combined with its potential for total system compromise, necessitates prompt action. Administrators should verify their current firmware versions against the provided ranges and apply updates as soon as they are made available by the vendor. Prioritize securing administrative accounts to mitigate the risk of this and similar vulnerabilities.

More Progress Software CVEs

Sources

Originally found and disclosed by Alex Williams from Converge Technology Solutions working with Trend Micro Zero Day Initiative, per the CVE Program record.