Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug a security issue" but the specific motivation for letting arbitrary persons change the value (Celsius, Fahrenheit, or Kelvin), seen by the device owner, is unclear.
References
| Link | Resource |
|---|---|
| https://github.com/pi-hole/web/pull/3077 | Issue Tracking |
| https://www.kiyell.com/The-Harmless-Pihole-Bug/ | Exploit Third Party Advisory |
Configurations
History
10 Oct 2025, 15:26
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/pi-hole/web/pull/3077 - Issue Tracking | |
| References | () https://www.kiyell.com/The-Harmless-Pihole-Bug/ - Exploit, Third Party Advisory | |
| First Time |
Pi-hole
Pi-hole pi-hole |
|
| CPE | cpe:2.3:a:pi-hole:pi-hole:*:*:*:*:*:*:*:* |
Information
Published : 2024-08-19 02:15
Updated : 2025-10-10 15:26
NVD link : CVE-2024-44069
Mitre link : CVE-2024-44069
CVE.ORG link : CVE-2024-44069
JSON object : View
Products Affected
pi-hole
- pi-hole
CWE
CWE-862
Missing Authorization
