Critical Vulnerabilities in Pi-hole Allow Arbitrary Code Execution
Article Content
- •Multiple vulnerabilities in Pi-hole allow arbitrary code execution via configuration imports.
- •Affected versions include all releases from FTL 6.0 to the latest, with critical CVEs identified.
- •Immediate patching is recommended to prevent potential exploitation through the web UI or API.
Recent advisories reveal multiple vulnerabilities in Pi-hole's configuration system, allowing authenticated users to bypass security checks and execute arbitrary code. The flaws stem from the Teleporter import feature, which lacks validation for configuration files, enabling malicious directives to be executed within the dnsmasq configuration. This includes the ability to run shell commands and execute scripts without prior access to the system. The vulnerabilities affect all versions of Pi-hole FTL from 6.0 to the latest release, with specific CVEs including GHSA-2794-hrj8-5jg9 and GHSA-ww5x-xx4x-qvjr. The issues were discovered during a code review and have not been publicly exploited yet, but the potential for exploitation is significant. Administrators are urged to apply patches immediately to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…