← Vulnerability feed

Vulnerability record · CVE-2020-7209 · published 13 February 2020

CVE-2020-7209: HP LinuxKI remote code execution via command injection

Hp · Linuxki

LinuxKI v6.0-1 and earlier contains a remote code execution flaw, fixed in release 6.0-2. The record gives no root-cause detail beyond the CWE being unspecified, but the CVSS vector and public exploit write-ups indicate a network-reachable command injection. Because the tool is a Linux diagnostic/performance toolkit, successful exploitation gives an attacker code execution in the context of the LinuxKI service or user.

9.8 CVSS 3.1 Critical EPSS 99% · top 0.1%
9.8CVSS 3.1 base score, v2 7.5
99%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network, unauthenticated, no-interaction exploitation and public exploit code, though it is not in KEV.

What it is

LinuxKI v6.0-1 and earlier contains a remote code execution flaw, fixed in release 6.0-2. The record gives no root-cause detail beyond the CWE being unspecified, but the CVSS vector and public exploit write-ups indicate a network-reachable command injection. Because the tool is a Linux diagnostic/performance toolkit, successful exploitation gives an attacker code execution in the context of the LinuxKI service or user.

Impact

An unauthenticated remote attacker can execute arbitrary commands on the host running the vulnerable LinuxKI version, leading to full compromise of confidentiality, integrity and availability.

Attack surface

Reached over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The exact exposed endpoint or parameter is not described in the record.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.98751, 99.9th percentile) and multiple Packet Storm references are tagged Exploit, indicating public exploit code exists.

What to do

  • Upgrade LinuxKI to release 6.0-2 or later immediately.
  • If upgrade is not possible, remove or restrict network access to the LinuxKI service using host firewalls or network segmentation.
  • Run LinuxKI with the least privilege necessary and avoid exposing it on untrusted networks.
  • Monitor vendor and Packet Storm advisories for updated guidance on the affected component.

Detection

  • Search process and command-line telemetry on LinuxKI hosts for unexpected shell or interpreter invocations spawned by the LinuxKI process.
  • Review web or service access logs for anomalous requests to LinuxKI endpoints, especially those containing shell metacharacters.
  • Alert on outbound network connections or file writes originating from the LinuxKI service account.
  • Inventory hosts running LinuxKI and confirm version is 6.0-2 or later.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-7209 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2020-7209), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.