CVE-2024-7591 is a critical improper input validation vulnerability in Progress LoadMaster that allows operating system command injection. The flaw affects LoadMaster 7.2.40.0 and later, all ECS versions, and Multi-Tenancy 7.1.35.4 and later. Insufficient validation of attacker-controlled input enables crafted requests to reach underlying system command execution paths, allowing unauthorized execution of OS commands on affected appliances or deployments.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a working proof-of-concept exploit for CVE-2024-7591, a remote code execution vulnerability in Kemp LoadMaster devices. The main script, KempExploit.py, automates the exploitation process: it connects to the target device, retrieves required tokens from the /progs/homepage endpoint, and then sends a crafted POST request to /progs/status/login with an encoded shell command. The command is executed on the target, and the output is returned in the HTTP response. The script supports both HTTP and HTTPS, custom ports, and allows the user to specify arbitrary commands. The auxiliary script, KempRCECommandGenerator.py, provides a utility to encode shell commands in the required format for manual exploitation or use with tools like Burp Suite. The repository is structured with two Python scripts (the exploit and the command encoder), a README with detailed usage instructions and examples, and a standard Apache 2.0 license. The exploit is operational, allowing for arbitrary command execution on vulnerable Kemp LoadMaster devices over the network.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.