{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-13444","assignerOrgId":"f9fea0b6-671e-4eea-8fde-31911902ae05","state":"PUBLISHED","assignerShortName":"ProgressSoftware","dateReserved":"2025-11-19T19:14:26.777Z","datePublished":"2026-01-13T14:26:50.661Z","dateUpdated":"2026-02-26T15:04:46.116Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["LoadMaster Appliance","MOVEit WAF Appliance","ECS Appliance","ObjectScale Appliance"],"product":"LoadMaster","vendor":"Progress Software","versions":[{"lessThan":"V7.2.62.2","status":"affected","version":"7.2.50","versionType":"custom"},{"lessThan":"V7.2.54.16","status":"affected","version":"7.2.50","versionType":"custom"}]},{"defaultStatus":"unaffected","platforms":["Multi Tenant LoadMaster"],"product":"Multi Tenant LoadMaster","vendor":"Progress Software","versions":[{"lessThan":"V7.1.35.15","status":"affected","version":"7.2.39","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Alex Williams from Converge Technology Solutions working with Trend Micro Zero Day Initiative"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters"}],"value":"OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters"}],"impacts":[{"descriptions":[{"lang":"en","value":"OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":8.4,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"description":"Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"f9fea0b6-671e-4eea-8fde-31911902ae05","shortName":"ProgressSoftware","dateUpdated":"2026-01-13T14:26:50.661Z"},"references":[{"tags":["vendor-advisory"],"url":"https://community.progress.com/s/article/LoadMaster-Vulnerabilities-CVE-2025-13444-CVE-2025-13447"},{"tags":["vendor-advisory"],"url":"https://community.progress.com/s/article/ECS-Connection-Manager-Vulnerabilities-CVE-2025-13444-CVE-2025-13447"},{"tags":["vendor-advisory"],"url":"https://community.progress.com/s/article/Connection-Manager-for-ObjectScale-Vulnerabilities-CVE-2025-13444-CVE-2025-13447"},{"tags":["vendor-advisory"],"url":"https://community.progress.com/s/article/MOVEit-WAF-Vulnerabilities-CVE-2025-13444-CVE-2025-13447"}],"source":{"discovery":"EXTERNAL"},"title":"OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster","x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2025-13444","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2026-01-14T04:57:18.478535Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-02-26T15:04:46.116Z"}}]}}