CVE-2020-8816 is a critical Remote Code Execution (RCE) vulnerability affecting Pi-hole Web v4.3.2 (AdminLTE), allowing privileged dashboard users to execute arbitrary code via a crafted DHCP static lease. With a CVSS score of 7.2 (HIGH) and an EPSS score indicating high exploitability, this vulnerability presents a significant risk. The attack vector is network-based with low complexity, enabling a complete compromise of confidentiality, integrity, and availability. This CVE is actively exploited in the wild, with public exploit code available in Metasploit and ExploitDB, and has garnered substantial community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.3.2CPE matchmatch criteria | cpe:2.3:a:pi-hole:pi-hole:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.