CVE-2020-12620: Pi-Hole
High severity, CVSS 7.8. EPSS: 1.5% chance of exploitation in the next 30 days.
Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command injection (shell metacharacters after an IP address).
Affected products
- Pi-hole Pi-Hole: before 5.0 (fixed in 5.0)
Published 2020-07-30. Last modified 2026-06-17.