CVE-2026-108107
Received Received - Intake

Unauthenticated SQL Injection in PHPNuxBill FreeRADIUS REST Endpoint

Vulnerability report for CVE-2026-108107, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: VulnCheck

Description

PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hotspotbilling phpnuxbill 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PHPNuxBill through 2025.3.20 has an unauthenticated SQL injection flaw in the radius.php FreeRADIUS REST endpoint. The vulnerability occurs because user-supplied parameters like username, macAddr, or nasid are directly interpolated into SQL queries via the whereRaw() function. Attackers can exploit this by sending specially crafted requests to the accounting or authenticate actions to extract sensitive data such as customer records and credentials using time-based blind SQL injection techniques.

Detection Guidance

Detecting this vulnerability requires checking for unauthenticated SQL injection attempts targeting the radius.php endpoint. Monitor web server logs for unusual requests containing parameters like username, macAddr, or nasid with SQL-like payloads (e.g., ' OR 1=1 --). Use tools like curl to test the endpoint for blind SQL injection by sending crafted requests and observing delays or errors.

Impact Analysis

This vulnerability allows attackers to gain unauthorized access to sensitive data, including customer records and credentials, without authentication. If exploited, it could lead to data breaches, unauthorized account access, financial loss, reputational damage, and potential legal consequences depending on the data exposed.

Compliance Impact

This vulnerability could severely impact compliance with GDPR and HIPAA by enabling unauthorized access to personal and sensitive data. GDPR requires protection of personal data and mandates breach notification, while HIPAA mandates safeguards for protected health information. A breach could result in regulatory fines, legal penalties, and mandatory audits.

Mitigation Strategies

Immediately update PHPNuxBill to the latest version (2025.3.20 or later) to patch the SQL injection flaw. If an update is unavailable, disable the FreeRADIUS REST endpoint in radius.php or restrict access via firewall rules to trusted IPs only. Implement input validation for all parameters passed to the endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108107. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart