TL;DR

CVE-2025-13447: Progress Software Kemp LoadMaster's delapikey function allows authenticated attackers to execute arbitrary commands, leading to remote code execution (CVSS Rating: 6.8).

What happened

['Progress Software Kemp LoadMaster suffers from an OS command injection vulnerability in the delapikey function']

Why it matters for ops

['This flaw enables authenticated users to inject and run arbitrary system commands on affected systems remotely, potentially leading to full control']

Mitigation

  • Apply vendor patches immediately
  • Limit administrative privileges to necessary users

Action items

  • Update Kemp LoadMaster to the latest version
  • Review and restrict access permissions for sensitive functions

Detection IOCs

  • Abnormal usage of delapikey function
  • Unexpected OS command executions from web interfaces

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-054/