CVE-2020-8816

pi-hole

Published 29 May 2020 · updated 17 Jun 2026 · Analyzed

7.2 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 10 Dec 2021, with a remediation deadline of 10 Jun 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

References