CVE-2025-13447 (GCVE-0-2025-13447)
Vulnerability from cvelistv5
Published
2026-01-13 14:31
Modified
2026-02-26 15:04
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)
Summary
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Progress Software | LoadMaster |
Version: 7.2.50 < V7.2.62.2 Version: 7.1.32 < V7.2.62.2 Version: 7.2.37 < V7.2.62.2 Version: 7.2.39 < V7.2.62.2 Version: 7.2.50 < V7.2.54.16 Version: 7.1.32 < V7.2.54.16 Version: 7.2.37 < V7.2.54.16 Version: 7.2.39 < V7.2.54.16 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-13447",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-01-14T04:57:19.495084Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-02-26T15:04:45.811Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"LoadMaster Appliance",
"MOVEit WAF Appliance",
"ECS Appliance",
"ObjectScale Appliance"
],
"product": "LoadMaster",
"vendor": "Progress Software",
"versions": [
{
"lessThan": "V7.2.62.2",
"status": "affected",
"version": "7.2.50",
"versionType": "custom"
},
{
"lessThan": "V7.2.62.2",
"status": "affected",
"version": "7.1.32",
"versionType": "custom"
},
{
"lessThan": "V7.2.62.2",
"status": "affected",
"version": "7.2.37",
"versionType": "custom"
},
{
"lessThan": "V7.2.62.2",
"status": "affected",
"version": "7.2.39",
"versionType": "custom"
},
{
"lessThan": "V7.2.54.16",
"status": "affected",
"version": "7.2.50",
"versionType": "custom"
},
{
"lessThan": "V7.2.54.16",
"status": "affected",
"version": "7.1.32",
"versionType": "custom"
},
{
"lessThan": "V7.2.54.16",
"status": "affected",
"version": "7.2.37",
"versionType": "custom"
},
{
"lessThan": "V7.2.54.16",
"status": "affected",
"version": "7.2.39",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Alex Williams from Converge Technology Solutions working with Trend Micro Zero Day Initiative"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with \u201cUser Administration\u201d permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters"
}
],
"value": "OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with \u201cUser Administration\u201d permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters"
}
],
"impacts": [
{
"descriptions": [
{
"lang": "en",
"value": "OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with \u201cUser Administration\u201d permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Improper Neutralization of Special Elements used in an OS Command (\u2018OS Command Injection\u2019)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-01-13T14:31:56.911Z",
"orgId": "f9fea0b6-671e-4eea-8fde-31911902ae05",
"shortName": "ProgressSoftware"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://community.progress.com/s/article/LoadMaster-Vulnerabilities-CVE-2025-13444-CVE-2025-13447"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://community.progress.com/s/article/ECS-Connection-Manager-Vulnerabilities-CVE-2025-13444-CVE-2025-13447"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://community.progress.com/s/article/Connection-Manager-for-ObjectScale-Vulnerabilities-CVE-2025-13444-CVE-2025-13447"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://community.progress.com/s/article/MOVEit-WAF-Vulnerabilities-CVE-2025-13444-CVE-2025-13447"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "f9fea0b6-671e-4eea-8fde-31911902ae05",
"assignerShortName": "ProgressSoftware",
"cveId": "CVE-2025-13447",
"datePublished": "2026-01-13T14:31:56.911Z",
"dateReserved": "2025-11-19T19:18:13.816Z",
"dateUpdated": "2026-02-26T15:04:45.811Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"vulnerability-lookup:meta": {
"vulnrichment": {
"containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2025-13447\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-01-14T04:57:19.495084Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-01-13T21:37:21.401Z\"}}], \"cna\": {\"title\": \"OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster\", \"source\": {\"discovery\": \"EXTERNAL\"}, \"credits\": [{\"lang\": \"en\", \"type\": \"finder\", \"value\": \"Alex Williams from Converge Technology Solutions working with Trend Micro Zero Day Initiative\"}], \"impacts\": [{\"descriptions\": [{\"lang\": \"en\", \"value\": \"OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with \\u201cUser Administration\\u201d permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters\"}]}], \"metrics\": [{\"format\": \"CVSS\", \"cvssV3_1\": {\"scope\": \"CHANGED\", \"version\": \"3.1\", \"baseScore\": 8.4, \"attackVector\": \"ADJACENT_NETWORK\", \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"HIGH\", \"confidentialityImpact\": \"HIGH\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}]}], \"affected\": [{\"vendor\": \"Progress Software\", \"product\": \"LoadMaster\", \"versions\": [{\"status\": \"affected\", \"version\": \"7.2.50\", \"lessThan\": \"V7.2.62.2\", \"versionType\": \"custom\"}, {\"status\": \"affected\", \"version\": \"7.1.32\", \"lessThan\": \"V7.2.62.2\", \"versionType\": \"custom\"}, {\"status\": \"affected\", \"version\": \"7.2.37\", \"lessThan\": \"V7.2.62.2\", \"versionType\": \"custom\"}, {\"status\": \"affected\", \"version\": \"7.2.39\", \"lessThan\": \"V7.2.62.2\", \"versionType\": \"custom\"}, {\"status\": \"affected\", \"version\": \"7.2.50\", \"lessThan\": \"V7.2.54.16\", \"versionType\": \"custom\"}, {\"status\": \"affected\", \"version\": \"7.1.32\", \"lessThan\": \"V7.2.54.16\", \"versionType\": \"custom\"}, {\"status\": \"affected\", \"version\": \"7.2.37\", \"lessThan\": \"V7.2.54.16\", \"versionType\": \"custom\"}, {\"status\": \"affected\", \"version\": \"7.2.39\", \"lessThan\": \"V7.2.54.16\", \"versionType\": \"custom\"}], \"platforms\": [\"LoadMaster Appliance\", \"MOVEit WAF Appliance\", \"ECS Appliance\", \"ObjectScale Appliance\"], \"defaultStatus\": \"unaffected\"}], \"references\": [{\"url\": \"https://community.progress.com/s/article/LoadMaster-Vulnerabilities-CVE-2025-13444-CVE-2025-13447\", \"tags\": [\"vendor-advisory\"]}, {\"url\": \"https://community.progress.com/s/article/ECS-Connection-Manager-Vulnerabilities-CVE-2025-13444-CVE-2025-13447\", \"tags\": [\"vendor-advisory\"]}, {\"url\": \"https://community.progress.com/s/article/Connection-Manager-for-ObjectScale-Vulnerabilities-CVE-2025-13444-CVE-2025-13447\", \"tags\": [\"vendor-advisory\"]}, {\"url\": \"https://community.progress.com/s/article/MOVEit-WAF-Vulnerabilities-CVE-2025-13444-CVE-2025-13447\", \"tags\": [\"vendor-advisory\"]}], \"x_generator\": {\"engine\": \"Vulnogram 0.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with \\u201cUser Administration\\u201d permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with \\u201cUser Administration\\u201d permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters\", \"base64\": false}]}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"description\": \"Improper Neutralization of Special Elements used in an OS Command (\\u2018OS Command Injection\\u2019)\"}]}], \"providerMetadata\": {\"orgId\": \"f9fea0b6-671e-4eea-8fde-31911902ae05\", \"shortName\": \"ProgressSoftware\", \"dateUpdated\": \"2026-01-13T14:31:56.911Z\"}}}",
"cveMetadata": "{\"cveId\": \"CVE-2025-13447\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-02-26T15:04:45.811Z\", \"dateReserved\": \"2025-11-19T19:18:13.816Z\", \"assignerOrgId\": \"f9fea0b6-671e-4eea-8fde-31911902ae05\", \"datePublished\": \"2026-01-13T14:31:56.911Z\", \"assignerShortName\": \"ProgressSoftware\"}",
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
}
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…