← Vulnerability feed

Vulnerability record · CVE-2020-8816 · published 29 May 2020

CVE-2020-8816: Pi-hole AdminLTE DHCP static lease OS command injection

Pi Hole · Pi Hole

Pi-hole Web v4.3.2 (AdminLTE) fails to sanitize the MAC address field of a DHCP static lease, allowing OS command injection. A privileged dashboard user can inject shell commands that execute on the underlying host, turning a web UI feature into host-level code execution.

7.2 CVSS 3.1 High CISA KEV since 10 Dec 2021 EPSS 78% · top 0.4% CWE-78 · OS command injection
7.2CVSS 3.1 base score, v2 6.5
78%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
15References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is in CISA KEV with a very high EPSS score and public exploit code, but exploitation requires authenticated privileged dashboard access, which limits reachability.

What it is

Pi-hole Web v4.3.2 (AdminLTE) fails to sanitize the MAC address field of a DHCP static lease, allowing OS command injection. A privileged dashboard user can inject shell commands that execute on the underlying host, turning a web UI feature into host-level code execution.

Impact

An attacker with dashboard access gains arbitrary command execution as the web server user on the Pi-hole host, enabling data theft, persistence, or lateral movement. Because Pi-hole is often the DNS resolver for an entire network, host compromise can affect all downstream clients.

Attack surface

Reached over the network through the Pi-hole web admin interface by submitting a crafted DHCP static lease; the CVSS vector (AV:N/AC:L/PR:H/UI:N) requires authenticated privileged dashboard access and no user interaction.

Exploitation

CISA added it to KEV on 2021-12-10, EPSS 30-day probability is 0.7819 (99.55th percentile), and references include an Exploit-tagged writeup, indicating active exploitation and public exploit availability.

What to do

  • Upgrade Pi-hole AdminLTE to v4.3.3 or later, which contains the fix.
  • Restrict web admin interface access to trusted management networks or VPN only.
  • Enforce least privilege and strong unique credentials for dashboard accounts; avoid shared admin logins.
  • Monitor and alert on unexpected outbound connections or process execution from the Pi-hole host.
  • Review DHCP static lease entries for suspicious characters in MAC address fields.

Detection

  • Search Pi-hole web/API logs for DHCP static lease submissions containing shell metacharacters (;, |, $(), backticks) in the MAC address field.
  • Monitor host process telemetry for shell or command interpreters spawned by the Pi-hole web server process.
  • Alert on unexpected child processes or network connections originating from the Pi-hole host outside normal DNS behavior.
  • Audit dashboard authentication logs for logins from unusual source IPs or at unusual times.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-8816 to the Known Exploited Vulnerabilities catalog on 10 December 2021 as "Pi-Hole AdminLTE Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 10 June 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/157861/Pi-Hole-4.3.2-DHCP-MAC-OS-Command-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/158737/Pi-hole-4.3.2-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
https://github.com/pi-hole/AdminLTE/commits/master PatchThird Party Advisory
https://github.com/pi-hole/AdminLTE/pull/1165 PatchThird Party Advisory
https://github.com/pi-hole/AdminLTE/releases/tag/v4.3.3 Release NotesThird Party Advisory
https://natedotred.wordpress.com/2020/03/28/cve-2020-8816-pi-hole-remote-code-execution/ Broken LinkExploitThird Party Advisory
https://twitter.com/Nate_Kappa/status/1243900213665902592?s=20 Broken LinkPress/Media Coverage
http://packetstormsecurity.com/files/157861/Pi-Hole-4.3.2-DHCP-MAC-OS-Command-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/158737/Pi-hole-4.3.2-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
https://github.com/pi-hole/AdminLTE/commits/master PatchThird Party Advisory
https://github.com/pi-hole/AdminLTE/pull/1165 PatchThird Party Advisory
https://github.com/pi-hole/AdminLTE/releases/tag/v4.3.3 Release NotesThird Party Advisory
https://natedotred.wordpress.com/2020/03/28/cve-2020-8816-pi-hole-remote-code-execution/ Broken LinkExploitThird Party Advisory
https://twitter.com/Nate_Kappa/status/1243900213665902592?s=20 Broken LinkPress/Media Coverage
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8816 US Government Resource

Track CVE-2020-8816 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2025-34087Pi-hole os command injection vulnerabilityAn authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, t…EPSS 7.0%8.8CVE-2026-50130Pi-hole vulnerabilityPi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with cod…EPSS 0.26%8.8CVE-2024-34361Pi-hole server-side request forgery (ssrf) vulnerabilityPi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior …EPSS 2.8%8.8CVE-2021-32706Pi-hole Web interface regex filter flaw enables code injectionPi-hole Web interface before version 5.5.1 has an unescaped period in the validDomainWildcard preg_match filter, allowing a malicious character to pa…EPSS 60%analysed8.8CVE-2021-29448Pi-hole ftldns cross-site scripting vulnerabilityPi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which ca…EPSS 0.67%8.8CVE-2020-11108Pi-hole Gravity updater unrestricted file upload leads to RCEThe Gravity updater in Pi-hole through 4.4 contains a code error in gravity_DownloadBlocklistFromUrl in gravity.sh that lets an authenticated user up…EPSS 78%analysed8.8CVE-2019-13051Pi-hole os command injection vulnerabilityPi-Hole 4.3 allows Command Injection.EPSS 12%7.8CVE-2021-29449Pi-hole improper privilege management vulnerabilityPi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discover…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2020-8816), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.