Executive brief
Pi-hole Web v4.3.2 (AdminLTE) is vulnerable to remote code execution. Privileged dashboard users can execute arbitrary OS commands via a crafted DHCP static lease, leading to full system compromise.
Affected products
- Pi-hole AdminLTE (Pi-hole Web) 4.3.2
Timeline
- 2020-03-28: disclosed: Initial public disclosure by researcher Nate Kappa
- 2021-12-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-12-10: advisory: NVD publication date