ZDI-26-055: Progress Software Kemp LoadMaster addapikey Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2025-13447.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-055?
The severity of ZDI-26-055 is critical due to its potential for remote code execution.
How do I fix ZDI-26-055?
To fix ZDI-26-055, update your Progress Software Kemp LoadMaster to the latest patched version provided by the vendor.
Who is affected by ZDI-26-055?
ZDI-26-055 affects installations of Progress Software Kemp LoadMaster that require authentication to exploit.
What type of vulnerability is ZDI-26-055?
ZDI-26-055 is a command injection vulnerability that allows for remote code execution.
Is authentication required to exploit ZDI-26-055?
Yes, authentication is required to exploit the ZDI-26-055 vulnerability.