An unauthenticated attacker on the adjacent network can run arbitrary OS commands on Progress LoadMaster appliances through unsanitised API endpoints, and the flaw is already being exploited.