CVE-2020-8816Disclosure(pi-hole / pi-hole)

LOWCVSS 7.2 · HIGHCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

0.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-06-10. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pi-hole

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
pi-hole

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-08: 1Technical Details · 2026-03-08: 103-08
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • TL;DR CTF with Onurcan@CtfWithOG
    Disclosure

    4/10 Pi-hole v3.1.4 is exposed. CVE-2020-8816 and EDB-48442 both offer authenticated RCE. But authenticated is the keyword. Default Pi-hole web creds (pi/raspberry) don’t work on the panel because we’re already in as a guest. The real surface is port 22.

    Post summary

    The post highlights that Pi‑hole v3.1.4 is vulnerable to CVE-2020-8816 and EDB-48442, providing authenticated RCE via port 22, but offers no patch, PoC, or exploitation details.

    1000035
    4 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppi-holepi-hole---

Explore more