CVE-2026-108108
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-108108, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: VulnCheck

Description

PHPNuxBill through 2025.3.20 contains an authentication bypass vulnerability in RADIUS CHAP verification because Password::chap_verify() returns true when the supplied response does not match. Attackers who know a valid customer or PPPoE username can log in through MikroTik hotspot or PPPoE CHAP with any incorrect password to obtain network access and consume that customer's plan.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hotspotbilling phpnuxbill 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PHPNuxBill through 2025.3.20 has an authentication bypass flaw in RADIUS CHAP verification. The Password::chap_verify() function incorrectly returns true even when the provided response does not match the expected password. This allows attackers with knowledge of a valid username to log in via MikroTik hotspot or PPPoE CHAP using any incorrect password, gaining unauthorized network access and consuming the victim's plan.

Detection Guidance

To detect this vulnerability, inspect the Password::chap_verify() function in system/autoload/Password.php for inverted comparison logic. Check if the function returns true when the CHAP response does not match the expected value. Verify authentication logs for successful logins with invalid passwords for valid usernames.

Impact Analysis

If you use PHPNuxBill for network authentication, attackers could bypass login controls to access your network or consume your paid plan. This may lead to unauthorized data usage, potential data breaches, or financial loss if billing plans are depleted by attackers.

Compliance Impact

This vulnerability could violate compliance requirements by allowing unauthorized access to sensitive data, potentially breaching GDPR or HIPAA. Unauthorized network access may lead to data exposure, violating confidentiality and integrity controls required by these regulations.

Mitigation Strategies

Update PHPNuxBill to version 2025.3.20 or later to fix the authentication bypass in RADIUS CHAP verification. Disable CHAP authentication for MikroTik hotspot or PPPoE if not required. Monitor network access logs for unusual login attempts with incorrect passwords.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108108. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart