CVE-2024-44069: Pi-Hole
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug a security issue" but the specific motivation for letting arbitrary persons change the value (Celsius, Fahrenheit, or Kelvin), seen by the device owner, is unclear.
Affected products
- Pi-hole Pi-Hole: before 6.0 (fixed in 6.0)
Published 2024-08-19. Last modified 2026-06-17.