Authentication Bypass Vulnerability in PHPNuxBill by HotSpotBilling
CVE-2026-108108

7.1HIGH

Key Information:

Vendor
CVE Published:
9 October 2026

What is CVE-2026-108108?

PHPNuxBill versions up to 2025.3.20 are susceptible to an authentication bypass flaw during RADIUS CHAP verification. The function Password::chap_verify() erroneously returns true despite verification failures, enabling attackers who possess a valid customer or PPPoE username to access the system with any incorrect password. This vulnerability allows unauthorized network access, potentially leading to the misuse of the customer's subscription plan.

Affected Version(s)

phpnuxbill 0 <= 2025.3.20

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kitu232
leediay153 from Viettel Post
.