ZDI-CAN-27594: ZDI-26-051: Progress Software Kemp LoadMaster delcert Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2025-13447.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27594?
ZDI-CAN-27594 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix ZDI-CAN-27594?
To fix ZDI-CAN-27594, ensure that you update your Progress Software Kemp LoadMaster to the latest available version that addresses this vulnerability.
What kind of attack is ZDI-CAN-27594 related to?
ZDI-CAN-27594 is related to command injection that allows execution of arbitrary code on affected systems.
What are the required conditions to exploit ZDI-CAN-27594?
Authentication is required for attackers to exploit ZDI-CAN-27594 on affected installations of Kemp LoadMaster.
Which products are affected by ZDI-CAN-27594?
ZDI-CAN-27594 specifically affects Progress Software Kemp LoadMaster installations.