TL;DR

Kemp LoadMaster's delcert command injection vulnerability enables authenticated attackers to execute arbitrary code on affected systems.

What happened

['Progress Software Kemp LoadMaster has a remote code execution vulnerability']

Why it matters for ops

['Exploit allows for unauthorized access and potential system compromise']

Mitigation

  • Update to the latest firmware version that addresses CVE-2025-13447
  • Limit access controls and monitor authentication logs

Action items

  • Apply available patches or updates for Kemp LoadMaster

Detection IOCs

  • Unexpected network traffic or behavior related to delcert command
  • Unusual login attempts from network-adjacent hosts

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-051/