CVE-2021-29449

MEDIUM

Pi-hole < 5.2.4 - OS Command Injection

Title source: rule
STIX 2.1

Description

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole core. See the referenced GitHub security advisory for details.

Exploits (1)

metasploit WORKING POC GREAT
by h00die · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/pihole_remove_commands_lpe.rb

Scores

CVSS v3 6.3
EPSS 0.1136
EPSS Percentile 93.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

Details

CWE
CWE-269 CWE-78
Status published
Products (2)
pi-hole/pi-hole < 5.2.4
pi-hole/pi-hole <= 5.2.4
Published Apr 14, 2021
Tracked Since Feb 18, 2026