CRITICAL🇵🇱 Wersja polska

CVE-2025-34087

CVSS 9.0v4.0pub. 2025-07-03upd. 2025-10-01

An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, the domain parameter is not properly sanitized, allowing an attacker to append OS commands to the domain string. These commands are executed on the underlying operating system with the privileges of the Pi-hole service user. This behavior was present in the legacy AdminLTE interface and has since been patched in later versions.

🤖 AI Analysis
How it works

When adding a domain to the allowlist through the AdminLTE interface, the domain parameter is not properly validated or sanitized. An attacker can append additional operating system commands to the domain string (e.g., using shell special characters). The payload passed this way is then forwarded to a system call and executed with the privileges of the user running the Pi-hole service.

Impact

An attacker can execute arbitrary commands on the server with the privileges of the Pi-hole process, which may lead to complete system compromise, data theft, or further lateral movement in the network.

Mitigation & patch

Pi-hole should be updated to version 4.0 or later, where the vulnerability has been removed. The patch is available in the repository: https://github.com/pi-hole/web/releases/tag/v4.0

Who is affected

Pi-hole in versions up to and including 3.3 using the AdminLTE interface

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Pi Hole

    APP
    Pi-Hole
    ≤ 3.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2020-8816HIGH7.2⚠ KEVsame product

Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHC...

CVE-2026-50130HIGH8.8PL ✓same product

Pi-hole: privilege escalation do root przez podmianę pliku logrotate

CVE-2024-44069HIGH7.5same product

Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of th...

CVE-2024-34361HIGH8.5same product

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side softw...

CVE-2024-28247HIGH7.6same product

The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-s...