Account Takeover Vulnerability in PHPNuxBill by HotSpot Billing
CVE-2026-108109

9.3CRITICAL

Key Information:

Vendor
CVE Published:
9 October 2026

What is CVE-2026-108109?

PHPNuxBill versions up to 2025.3.20 contain a significant vulnerability in the password reset process, specifically within the 'forgot' controller. This flaw allows attackers to attempt unlimited guesses on the 6-digit OTP code, provided they know the username of a targeted customer. Since there are no restrictions on the number of attempts, attackers can eventually discover the OTP and hijack the associated account by intercepting the response which reveals the newly set password.

Affected Version(s)

phpnuxbill 0 <= 2025.3.20

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tonghuaroot
leediay153 from Viettel Post
.