ZDI-CAN-27591: ZDI-26-053: Progress Software Kemp LoadMaster listapikeys Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2025-13447.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27591?
The severity of ZDI-CAN-27591 is considered high due to the potential for remote code execution.
How do I fix ZDI-CAN-27591?
To mitigate the ZDI-CAN-27591 vulnerability, update Progress Software Kemp LoadMaster to the latest patched version.
Who can exploit ZDI-CAN-27591?
ZDI-CAN-27591 can be exploited by network-adjacent attackers who have authentication access.
What are the consequences of ZDI-CAN-27591?
Exploitation of ZDI-CAN-27591 can lead to arbitrary code execution on affected installations.
What versions of Progress Software Kemp LoadMaster are affected by ZDI-CAN-27591?
All affected versions of Progress Software Kemp LoadMaster that allow command injection are impacted by ZDI-CAN-27591.