CVE-2025-13447
8.4Progress Software · LoadMaster
An OS command injection vulnerability in the Progress LoadMaster API allows an authenticated user with administrative privileges to execute arbitrary commands on the underlying appliance.
Executive summary
An OS command injection vulnerability in Progress LoadMaster allows authenticated attackers with administrative access to achieve remote code execution on the appliance.
Vulnerability
This vulnerability is an OS command injection flaw occurring within the API input parameters. It requires an attacker to possess valid User Administration credentials to trigger the execution of arbitrary commands.
Business impact
A successful exploit grants the attacker total control over the LoadMaster appliance, which often serves as a critical gateway for network traffic and load balancing. Given the CVSS score of 8.4, this high severity flaw poses a significant risk of lateral movement, data interception, and total system compromise. Organizations relying on these appliances for service availability face potential downtime and severe security breaches if these administrative interfaces are compromised.
Remediation
Immediate Action: Upgrade the LoadMaster firmware to version 7.2.62.2 or 7.2.54.16, as specified by the vendor advisory.
Proactive Monitoring: Review administrative access logs for suspicious API requests or unexpected command execution patterns originating from authorized accounts.
Compensating Controls: Restrict access to the LoadMaster management interface to trusted management networks or VPNs to limit the exposure of the API to unauthorized users.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the severity of this remote code execution vulnerability, administrators must prioritize patching the affected LoadMaster appliances. Ensure that administrative accounts are secured with strong, unique credentials and that access to the management API is strictly controlled to prevent exploitation by compromised or malicious internal users.
More Progress Software CVEs
Sources
Originally found and disclosed by Alex Williams from Converge Technology Solutions working with Trend Micro Zero Day Initiative, per the CVE Program record.