CVE-2020-8816
pi-hole
Published 29 May 2020 · updated 17 Jun 2026 · Analyzed
7.2 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 10 Dec 2021, with a remediation deadline of 10 Jun 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
References
- packetstormsecurity.com/files/157861/Pi-Hole-4.3.2-DHCP-MAC-OS-Command-Execution.html · Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/158737/Pi-hole-4.3.2-Remote-Code-Execution.html · Third Party Advisory, VDB Entry
- github.com/pi-hole/AdminLTE/commits/master · Patch, Third Party Advisory
- github.com/pi-hole/AdminLTE/pull/1165 · Patch, Third Party Advisory
- github.com/pi-hole/AdminLTE/releases/tag/v4.3.3 · Release Notes, Third Party Advisory
- natedotred.wordpress.com/2020/03/28/cve-2020-8816-pi-hole-remote-code-execution/ · Broken Link, Exploit, Third Party Advisory
- twitter.com/Nate_Kappa/status/1243900213665902592?s=20 · Broken Link, Press/Media Coverage
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8816 · US Government Resource