CVE-2020-8816
Summary
| CVE | CVE-2020-8816 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-05-29 19:15:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease. |
Risk And Classification
EPSS: 0.907750000 probability, percentile 0.996220000 (date 2026-04-02)
CISA KEV: Listed on 2021-12-10; due 2022-06-10; ransomware use Unknown
Problem Types: CWE-78
CISA Known Exploited Vulnerability
| Vendor | Pi-hole |
|---|---|
| Product | AdminLTE |
| Name | Pi-Hole AdminLTE Remote Code Execution Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2020-8816 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release Pi-hole Web version 4.3.3 · pi-hole/AdminLTE · GitHub | MISC | github.com | |
| Pi-hole 4.3.2 Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| N̜̣̹͗ͬͫ͗ã͓͕͔̟̓̑̔t̺͎͕͔̂͋ͦë̙̉̽ ????wear your mask???? na Twitterze: "I discovered and disclosed this fancy RCE: CVE-2020-8816 - Pi-hole Remote Code Execution https://t.co/Q9aPeEq8Wj… " | MISC | twitter.com | |
| Fix potential code injection on MAC address validator by PromoFaux · Pull Request #1165 · pi-hole/AdminLTE · GitHub | MISC | github.com | |
| Commits · pi-hole/AdminLTE · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Pi-Hole 4.3.2 DHCP MAC OS Command Execution ≈ Packet Storm | CONFIRM | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| CVE-2020-8816 – Pi-hole Remote Code Execution – Nate’s Blog | MISC | natedotred.wordpress.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 376490 Pi-Hole Web Interface Remote Code Execution (RCE) Vulnerability