CVE-2025-1758
Progress LoadMaster vulnerability analysis and mitigation

Overview

CVE-2025-1758 is a critical buffer overflow vulnerability discovered in Progress Software's Kemp LoadMaster, an application delivery controller (ADC) and load balancer. The vulnerability was identified in March 2025 and affects multiple versions of LoadMaster (7.2.40.0 and above), ECS (all versions), and Multi-Tenancy (7.1.35.4 and above). The flaw is specifically located in the mangle executable component of LoadMaster (NVD, SecurityOnline).

Technical details

The vulnerability is classified as a stack-based buffer overflow (CWE-121) that stems from improper input validation. The issue specifically occurs in the mangle executable where there is a lack of proper validation of user-supplied data length before copying it to a fixed-length stack-based buffer. The vulnerability has received a critical CVSS score of 9.8, indicating its severe nature. The flaw requires no authentication to exploit, making it particularly dangerous (SecurityOnline).

Impact

The vulnerability enables unauthenticated remote attackers to execute arbitrary code on affected systems. When exploited, the attack runs in the context of the bal user, potentially allowing attackers to manipulate configurations, steal sensitive data, or disrupt system operations. Given LoadMaster's critical role in delivering SSL offloading, content switching, URL rewriting, and compression for enterprise applications, successful exploitation could significantly impact an organization's application delivery infrastructure (SecurityOnline).

Mitigation and workarounds

Progress Software has addressed this vulnerability by releasing LoadMaster version 7.2.61.1. Organizations are strongly advised to immediately update to this patched version to protect against potential exploitation (SecurityOnline).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management