Vulnerability record · CVE-2020-8816 · published 29 May 2020
CVE-2020-8816: Pi-hole AdminLTE DHCP static lease OS command injection
Pi Hole · Pi Hole
Pi-hole Web v4.3.2 (AdminLTE) fails to sanitize the MAC address field of a DHCP static lease, allowing OS command injection. A privileged dashboard user can inject shell commands that execute on the underlying host, turning a web UI feature into host-level code execution.
Description
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with a very high EPSS score and public exploit code, but exploitation requires authenticated privileged dashboard access, which limits reachability.
What it is
Pi-hole Web v4.3.2 (AdminLTE) fails to sanitize the MAC address field of a DHCP static lease, allowing OS command injection. A privileged dashboard user can inject shell commands that execute on the underlying host, turning a web UI feature into host-level code execution.
Impact
An attacker with dashboard access gains arbitrary command execution as the web server user on the Pi-hole host, enabling data theft, persistence, or lateral movement. Because Pi-hole is often the DNS resolver for an entire network, host compromise can affect all downstream clients.
Attack surface
Reached over the network through the Pi-hole web admin interface by submitting a crafted DHCP static lease; the CVSS vector (AV:N/AC:L/PR:H/UI:N) requires authenticated privileged dashboard access and no user interaction.
Exploitation
CISA added it to KEV on 2021-12-10, EPSS 30-day probability is 0.7819 (99.55th percentile), and references include an Exploit-tagged writeup, indicating active exploitation and public exploit availability.
What to do
- Upgrade Pi-hole AdminLTE to v4.3.3 or later, which contains the fix.
- Restrict web admin interface access to trusted management networks or VPN only.
- Enforce least privilege and strong unique credentials for dashboard accounts; avoid shared admin logins.
- Monitor and alert on unexpected outbound connections or process execution from the Pi-hole host.
- Review DHCP static lease entries for suspicious characters in MAC address fields.
Detection
- Search Pi-hole web/API logs for DHCP static lease submissions containing shell metacharacters (;, |, $(), backticks) in the MAC address field.
- Monitor host process telemetry for shell or command interpreters spawned by the Pi-hole web server process.
- Alert on unexpected child processes or network connections originating from the Pi-hole host outside normal DNS behavior.
- Audit dashboard authentication logs for logins from unusual source IPs or at unusual times.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-8816 to the Known Exploited Vulnerabilities catalog on 10 December 2021 as "Pi-Hole AdminLTE Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 10 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-8816 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8816), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.