EXPOSURES › CVE-2020-8816
CVE-2020-8816
HIGH ⌖ ON CISA KEV · EXPLOITEDPi-hole AdminLTE allowed remote code execution via a crafted DHCP static lease to privileged dashboard users.
A remote code execution vulnerability in Pi-hole AdminLTE (CVE-2020-8816) allowed attackers to execute arbitrary code on systems running Pi-hole Web v4.3.2 by exploiting a crafted DHCP static lease. DIB organizations should care because this flaw was actively exploited in the wild (KEV), enabling attackers to compromise network security monitoring and potentially pivot to other systems. Organizations must ensure they are running patched versions of Pi-hole and restrict access to privileged dashboard users to mitigate this risk.
Shame score — The vulnerability was actively exploited in the wild and allowed remote code execution to privileged users, indicating a significant security oversight that could have been mitigated with proper patching and access controls.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.