PT-2020-6849 · Unknown · Pi-Hole Web
Nate-Red
·
Published
2020-03-28
·
Updated
2025-11-10
·
CVE-2020-8816
CVSS v3.1
9.1
Critical
| Vector | AC:L/AV:N/A:H/C:H/I:H/PR:H/S:C/UI:N |
Name of the Vulnerable Software and Affected Versions
Pi-hole Web version 4.3.2
Description
The issue allows remote code execution by privileged dashboard users via a crafted DHCP static lease. This is due to the failure to neutralize special elements used in the operating system command. Exploitation of this issue may allow a remote attacker to execute arbitrary code.
Recommendations
For version 4.3.2, update to a version that includes a fix for this issue to prevent remote code execution. As a temporary workaround, consider restricting access to the dashboard and limiting the ability to create or modify DHCP static leases until a patch is available.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pi-Hole Web