CVE-2019-18909: HP Thinpro
High severity, CVSS 8.0. EPSS: 2.2% chance of exploitation in the next 30 days.
The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges.
Affected products
- HP Thinpro: version 6.2 only; version 6.2.1 only; version 7.0 only; version 7.1 only
Published 2019-11-22. Last modified 2026-06-17.