OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster
Summary
| CVE | CVE-2025-13444 |
|---|---|
| State | PUBLISHED |
| Assigner | ProgressSoftware |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-01-13 15:15:57 UTC |
| Updated | 2026-08-10 20:20:00 UTC |
| Description | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters |
Risk And Classification
Primary CVSS: v3.1 6.8 MEDIUM from [email protected]
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-78 | Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 6.8 | MEDIUM | CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 8.4 | HIGH | CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 8.4 | HIGH | CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
AdjacentAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Progress | Connection Manager For Objectscale | All | All | All | All |
| Application | Progress | Ecs Connection Manager | All | All | All | All |
| Operating System | Progress | Loadmaster | All | All | All | All |
| Application | Progress | Moveit Web Application Firewall | 7.2.62.1 | All | All | All |
| Application | Progress | Multi-tenant Hypervisor | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Progress Software | LoadMaster | affected 7.2.50 V7.2.62.2 custom | LoadMaster Appliance, MOVEit WAF Appliance, ECS Appliance, ObjectScale Appliance |
| CNA | Progress Software | LoadMaster | affected 7.2.50 V7.2.54.16 custom | LoadMaster Appliance, MOVEit WAF Appliance, ECS Appliance, ObjectScale Appliance |
| CNA | Progress Software | Multi Tenant LoadMaster | affected 7.2.39 V7.1.35.15 custom | Multi Tenant LoadMaster |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| community.progress.com/s/article/ECS-Connection-Manager-Vulnerabilities-CVE-2025-134... | [email protected] | community.progress.com | Vendor Advisory |
| community.progress.com/s/article/Connection-Manager-for-ObjectScale-Vulnerabilities-... | [email protected] | community.progress.com | Vendor Advisory |
| community.progress.com/s/article/LoadMaster-Vulnerabilities-CVE-2025-13444-CVE-2025-... | [email protected] | community.progress.com | Vendor Advisory |
| community.progress.com/s/article/MOVEit-WAF-Vulnerabilities-CVE-2025-13444-CVE-2025-... | [email protected] | community.progress.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Alex Williams from Converge Technology Solutions working with Trend Micro Zero Day Initiative (en)
There are currently no legacy QID mappings associated with this CVE.