ZDI-26-052: Progress Software Kemp LoadMaster getcipherset Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2025-13444.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-052?
ZDI-26-052 is rated as a critical vulnerability due to its potential for remote code execution.
How do I fix ZDI-26-052?
To fix ZDI-26-052, ensure that you apply the latest security updates provided by Progress Software for Kemp LoadMaster.
Who is affected by ZDI-26-052?
ZDI-26-052 affects installations of Progress Software Kemp LoadMaster that have not been patched.
What type of attacks can be executed through ZDI-26-052?
ZDI-26-052 allows network-adjacent attackers to execute arbitrary code on vulnerable systems.
Is authentication required to exploit ZDI-26-052?
Yes, authentication is required to exploit the ZDI-26-052 vulnerability.