ZDI-CAN-27596: ZDI-26-055: Progress Software Kemp LoadMaster addapikey Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2025-13447.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27596?
ZDI-CAN-27596 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix ZDI-CAN-27596?
To fix ZDI-CAN-27596, ensure you update your Progress Software Kemp LoadMaster to the latest patched version provided by the vendor.
What type of attack does ZDI-CAN-27596 enable?
ZDI-CAN-27596 enables network-adjacent attackers to execute arbitrary code on affected installations of Kemp LoadMaster.
Is authentication required to exploit ZDI-CAN-27596?
Yes, authentication is required to exploit the ZDI-CAN-27596 vulnerability.
What products are affected by ZDI-CAN-27596?
The affected product for ZDI-CAN-27596 is Progress Software Kemp LoadMaster.