CVE-2024-1212 is a pre-authentication OS command injection vulnerability in Kemp Technologies LoadMaster management interfaces on Linux. Improper sanitization of Basic Authentication header values processed by the management API permits attacker-controlled input to reach a system command execution call. A remote unauthenticated attacker can inject shell syntax into a crafted authorization value and execute arbitrary operating-system commands on the affected appliance.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a working exploit for CVE-2024-1212, an unauthenticated command injection vulnerability in Progress Kemp LoadMaster. The repository consists of a Python script ('cve_2024_1212_exploit.py') and a detailed README. The exploit script allows an attacker to execute arbitrary commands on a vulnerable LoadMaster device by sending a crafted HTTP GET request to the '/access/set' endpoint, injecting the command via the 'value' parameter. The script supports proxying requests (for interception or anonymity), randomizes the User-Agent header to evade basic detection, and can log output to a file. The README provides usage instructions, options, and example commands. The exploit is operational and can be used for remote unauthenticated command execution on affected devices. The main fingerprintable endpoint is '/access/set', and the exploit leverages a specific Authorization header. The code is straightforward, with a single entry point and no extraneous files.
This repository contains a single Metasploit module targeting an unauthenticated command injection vulnerability (CVE-2024-1212) in Progress Kemp LoadMaster appliances. The exploit leverages a flaw in the HTTP Authorization header processing on the '/access/set' endpoint, allowing remote attackers to execute arbitrary commands without authentication. The module is written in Ruby and follows the standard Metasploit structure, including methods for exploitation, vulnerability checking, and session handling. The default payload is a Meterpreter reverse shell, but arbitrary commands can be executed. The exploit is operational and can be used to gain remote shell access to vulnerable LoadMaster instances. The module also creates a temporary flag file in '/tmp/' to help manage repeated exploitation. The only file in the repository is the Metasploit module itself, and it is fully self-contained.
This repository contains a single Metasploit module targeting a local privilege escalation vulnerability (CVE-2024-1212) in Progress Kemp LoadMaster appliances. The exploit abuses the fact that certain binaries (such as /bin/loadkeys) are allowed to auto-elevate via sudo based on their filename, but are not write-protected from the default 'bal' user. The module overwrites such a binary with a payload, then executes it via sudo to gain root privileges. The module supports both binary and command payloads, including reverse shells and meterpreter sessions. It includes fingerprinting logic to verify the target is a Kemp LoadMaster by checking for specific files. The exploit is operational and weaponized, as it is part of the Metasploit framework and supports customizable payloads. The main attack vector is local, requiring shell access as the 'bal' user. The module interacts with several fingerprintable file paths, including /bin/loadkeys, /usr/wui/index.js, /etc/motd, /usr/wui/eula.kemp.html, and uses /tmp for temporary files.
This repository is a proof-of-concept (PoC) exploit for CVE-2024-1212, an unauthenticated command injection vulnerability in Kemp LoadMaster appliances. The main file, 'exploit.py', is a Python script that allows users to scan single or multiple targets for the vulnerability, execute arbitrary shell commands on vulnerable devices, and interact with them via an interactive shell. The exploit works by sending a specially crafted HTTP GET request to the '/access/set?param=enableapi&value=1' endpoint, injecting commands into the HTTP Basic Auth username field. The script supports multi-threaded scanning and can save a list of vulnerable targets to an output file. The repository also includes a 'requirements.txt' for dependencies and a detailed 'README.md' with usage instructions and privilege escalation guidance. The exploit is unauthenticated, network-based, and targets Kemp LoadMaster devices. No hardcoded payload is provided beyond the command injection mechanism, and the exploit is intended for educational and authorized security testing purposes only.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously exploited critical Progress Kemp LoadMaster vulnerability mentioned for comparison/background.
A critical OS command injection vulnerability in Progress Kemp LoadMaster referenced as a prior flaw that also saw active exploitation efforts.
A previous critical Progress Kemp LoadMaster command injection vulnerability that was added to CISA's Known Exploited Vulnerabilities catalog after confirmed in-the-wild exploitation.
A prior unauthenticated command injection vulnerability in Progress Kemp LoadMaster, cited as a historical parallel to CVE-2026-8037.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.