Description
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters
Problem types
Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)
Product status
7.2.50 (custom) before V7.2.62.2
7.2.50 (custom) before V7.2.54.16
7.2.39 (custom) before V7.1.35.15
Credits
Alex Williams from Converge Technology Solutions working with Trend Micro Zero Day Initiative
References
community.progress.com/...ties-CVE-2025-13444-CVE-2025-13447
community.progress.com/...ties-CVE-2025-13444-CVE-2025-13447
community.progress.com/...ties-CVE-2025-13444-CVE-2025-13447
community.progress.com/...ties-CVE-2025-13444-CVE-2025-13447