ZDI-26-053: Progress Software Kemp LoadMaster listapikeys Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2025-13447.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-053?
ZDI-26-053 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix ZDI-26-053?
To mitigate the ZDI-26-053 vulnerability, ensure that your Progress Software Kemp LoadMaster is updated to the latest version with the provided security patches.
Who is impacted by ZDI-26-053?
ZDI-26-053 affects installations of Progress Software Kemp LoadMaster that are accessible to network-adjacent attackers.
Can ZDI-26-053 be exploited without authentication?
No, exploitation of ZDI-26-053 requires authentication to access the vulnerable command injection functionality.
What type of vulnerability is ZDI-26-053?
ZDI-26-053 is categorized as a command injection vulnerability that leads to remote code execution.