High severity8.4NVD Advisory· Published Jan 13, 2026· Updated Jun 17, 2026
CVE-2025-13447
CVE-2025-13447
Description
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters
Affected products
10(expand)+ 2 more
- (no CPE)
- cpe:2.3:a:progress:loadmaster:*:*:*:*:ltsf:*:*:*range: <7.2.54.16
- cpe:2.3:a:progress:loadmaster:*:*:*:*:ga:*:*:*range: <7.2.62.2
(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:progress:connection_manager_for_objectscale*:*:*:*:*:*:*:*:*range: <7.2.62.2
- cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*Range: <7.2.62.2
- cpe:2.3:a:progress:moveit_waf:7.2.62.1:*:*:*:*:*:*:*
- cpe:2.3:a:progress:multi-tenant_hypervisor:*:*:*:*:*:*:*:*Range: <7.1.35.15
- Range: 7.2.50
Patches
Vulnerability mechanics
References
4- community.progress.com/s/article/Connection-Manager-for-ObjectScale-Vulnerabilities-CVE-2025-13444-CVE-2025-13447nvdVendor Advisory
- community.progress.com/s/article/ECS-Connection-Manager-Vulnerabilities-CVE-2025-13444-CVE-2025-13447nvdVendor Advisory
- community.progress.com/s/article/LoadMaster-Vulnerabilities-CVE-2025-13444-CVE-2025-13447nvdVendor Advisory
- community.progress.com/s/article/MOVEit-WAF-Vulnerabilities-CVE-2025-13444-CVE-2025-13447nvdVendor Advisory
News mentions
0No linked articles in our index yet.