ZeroHour

CVE-2020-8816

KEV PoC large

Authenticated Command Injection RCE in Pi-hole AdminLTE Web Dashboard

CISA: Pi-Hole AdminLTE Remote Code Execution Vulnerability

CVSS 3.1
7.2 high
EPSS
78%p100
Published
()
KEV added
AI analysis

CVE-2020-8816 is an OS command injection flaw (CWE-78) in Pi-hole's web dashboard, AdminLTE (Pi-hole Web), version 4.3.2. A privileged dashboard user can trigger remote code execution by adding a crafted DHCP static lease, causing injected commands to run on the Pi-hole host. An attacker with an authenticated admin session gains code execution on the DNS appliance, yielding high impact on confidentiality, integrity and availability of that system and the networks whose DNS it handles. Any Pi-hole deployment running the affected AdminLTE web interface is affected, with the greatest risk where the admin panel is reachable from networks an attacker can access. The flaw is listed in CISA's Known Exploited Vulnerabilities Catalog (added 2021-12-10), has a public proof-of-concept, and carries a very high EPSS (~78% probability of exploitation within 30 days), so it should be treated as actively exploited.

What to do: Upgrade Pi-hole Web (AdminLTE) to any release newer than v4.3.2 per vendor instructions and treat this as urgent because the flaw is in CISA's KEV. In the interim, keep the admin dashboard off the public internet (restrict to LAN/VPN with strong authentication), review configured DHCP static leases for injected commands, and check web server logs for evidence of exploitation.

Affected
Pi-hole Web (AdminLTE) dashboardv4.3.2 (fixed in later releases)
Estimated exposure
large≈ hundreds of thousands of Pi-hole instances, of which tens of thousands have the dashboard exposed to the internet — Pi-hole is one of the most widely deployed self-hosted DNS ad blockers across hobbyist and small-office networks (its dashboard appears tens of thousands of times in public internet scans), so a six-figure install base is plausible, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

CISA Known Exploited Vulnerability
Affected
Pi-hole AdminLTE
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
pi-hole
Products
pi-hole
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news