CVE-2020-8816
KEV PoC largeAuthenticated Command Injection RCE in Pi-hole AdminLTE Web Dashboard
CISA: Pi-Hole AdminLTE Remote Code Execution Vulnerability
CVE-2020-8816 is an OS command injection flaw (CWE-78) in Pi-hole's web dashboard, AdminLTE (Pi-hole Web), version 4.3.2. A privileged dashboard user can trigger remote code execution by adding a crafted DHCP static lease, causing injected commands to run on the Pi-hole host. An attacker with an authenticated admin session gains code execution on the DNS appliance, yielding high impact on confidentiality, integrity and availability of that system and the networks whose DNS it handles. Any Pi-hole deployment running the affected AdminLTE web interface is affected, with the greatest risk where the admin panel is reachable from networks an attacker can access. The flaw is listed in CISA's Known Exploited Vulnerabilities Catalog (added 2021-12-10), has a public proof-of-concept, and carries a very high EPSS (~78% probability of exploitation within 30 days), so it should be treated as actively exploited.
What to do: Upgrade Pi-hole Web (AdminLTE) to any release newer than v4.3.2 per vendor instructions and treat this as urgent because the flaw is in CISA's KEV. In the interim, keep the admin dashboard off the public internet (restrict to LAN/VPN with strong authentication), review configured DHCP static leases for injected commands, and check web server logs for evidence of exploitation.
| Pi-hole Web (AdminLTE) dashboard | v4.3.2 (fixed in later releases) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
- Affected
- Pi-hole AdminLTE
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- pi-hole
- Products
- pi-hole
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H