Vulnerability record · CVE-2021-32706 · published 4 August 2021
CVE-2021-32706: Pi-hole Web interface regex filter flaw enables code injection
Pi Hole · Pi Hole
Pi-hole Web interface before version 5.5.1 has an unescaped period in the validDomainWildcard preg_match filter, allowing a malicious character to pass through. This permits code execution, directory listing, and overwriting of sensitive files. The flaw is a code injection issue in a widely used DNS management interface.
Description
Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the `validDomainWildcard` preg_match filter allows a malicious character through that can be used to execute code, list directories, and overwrite sensitive files. The issue lies in the fact that one of the periods is not escaped, allowing any character to be used in its place. A patch for this vulnerability was released in version 5.5.1.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS score is 8.8 (HIGH) and EPSS is 0.60181 with an Exploit reference, but no KEV listing and exploitation requires authentication.
What it is
Pi-hole Web interface before version 5.5.1 has an unescaped period in the validDomainWildcard preg_match filter, allowing a malicious character to pass through. This permits code execution, directory listing, and overwriting of sensitive files. The flaw is a code injection issue in a widely used DNS management interface.
Impact
An authenticated attacker can execute arbitrary code, list directories, and overwrite sensitive files on the Pi-hole host. This can lead to full compromise of the Pi-hole instance and its underlying system.
Attack surface
The vulnerability is reachable over the network through the Pi-hole Web interface. The CVSS vector indicates low privileges are required and no user interaction is needed.
Exploitation
No CISA KEV listing. EPSS probability is 0.60181 (99th percentile), indicating high likelihood of exploitation. References include an Exploit tag, suggesting public exploit information exists.
What to do
- Upgrade Pi-hole Web interface to version 5.5.1 or later immediately.
- Restrict network access to the Pi-hole Web interface to trusted administrators only.
- Enforce strong authentication and least privilege for Pi-hole administrative accounts.
- Monitor for unexpected file modifications or command execution on Pi-hole hosts.
- Review and harden any custom domain wildcard configurations.
Detection
- Monitor web server logs for requests containing unusual characters in domain wildcard parameters.
- Alert on unexpected file writes or directory listings in Pi-hole web directories.
- Use file integrity monitoring on sensitive Pi-hole configuration and system files.
- Audit Pi-hole admin user activity for anomalous commands or file operations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/pi-hole/AdminLTE/releases/tag/v5.5.1 | Release NotesThird Party Advisory |
| https://github.com/pi-hole/AdminLTE/security/advisories/GHSA-5cm9-6p3m-v259 | ExploitThird Party Advisory |
| https://github.com/pi-hole/AdminLTE/releases/tag/v5.5.1 | Release NotesThird Party Advisory |
| https://github.com/pi-hole/AdminLTE/security/advisories/GHSA-5cm9-6p3m-v259 | ExploitThird Party Advisory |
Track CVE-2021-32706 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-32706), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.