Skip to content
Saturday, October 10, 2026AboutContactRSS
PHPNuxBill FreeRADIUS Endpoint Exposes Customer Data via Unauthenticated SQLi
Vulnerabilities

PHPNuxBill FreeRADIUS Endpoint Exposes Customer Data via Unauthenticated SQLi

A critical vulnerability in PHPNuxBill allows remote attackers to steal credentials through a flawed FreeRADIUS API endpoint without authentication.

Key points

  • CVE-2026-108107 is rated Critical with a CVSS score of 9.3.
  • The flaw exists in PHPNuxBill versions through 2025.3.20.
  • Attackers exploit crafted parameters in radius.php to extract data via blind SQL injection.

A critical security flaw in PHPNuxBill’s FreeRADIUS integration allows unauthenticated attackers to steal customer credentials. The vulnerability stems from improper handling of request parameters in the application’s REST endpoint.

What happened

According to the National Vulnerability Database, PHPNuxBill versions through 2025.3.20 contain an unauthenticated SQL injection vulnerability. The issue is located in the `radius.php` file, which serves as the FreeRADIUS REST endpoint. The application fails to properly sanitize input, interpolating request parameters directly into `whereRaw()` database queries.

Attackers can exploit this by sending crafted requests to the accounting or authenticate actions. Specifically, they can manipulate the `username`, `macAddr`, or `nasid` parameters. This manipulation enables time-based blind SQL injection. By analyzing response times, an attacker can extract sensitive information, including customer records and login credentials. The vulnerability is classified under CWE-89, which covers SQL injection weaknesses.

Why it matters

The flaw is rated Critical with a CVSS score of 9.3, indicating a severe risk to exposed systems. Because the vulnerability is unauthenticated, attackers do not need valid login credentials to attempt exploitation. This lowers the barrier for malicious actors, including automated scanners and botnets.

The impact is significant because the endpoint handles sensitive authentication and accounting data for network access. Compromise of this endpoint can lead to the full extraction of customer databases. For IT managers using PHPNuxBill for hotspot billing or network management, this represents a direct path to credential theft and data breach. The affected product, also known as hotspotbilling phpnuxbill, is widely used in managed network environments.

What to watch

  • Monitor for unusual traffic patterns targeting the `radius.php` endpoint.
  • Check application logs for repeated failed authentication or accounting requests with anomalous parameter values.
  • Look for significant delays in API response times, which may indicate time-based blind SQL injection attempts.
  • Verify that all instances of PHPNuxBill are identified in your asset inventory to assess exposure.

What to do and how to stay safe: PHPNuxBill

  • Restrict network access to the PHPNuxBill FreeRADIUS endpoint to trusted management networks only, using firewalls or ACLs.
  • Deploy a Web Application Firewall (WAF) with rules tuned to detect SQL injection patterns in `username`, `macAddr`, and `nasid` parameters.
  • Enable detailed logging on the application server to capture full request payloads for forensic analysis if an attack occurs.
  • Verify if the vendor has released a patched version; if not, consider isolating the service or disabling remote access until a fix is confirmed.

General security guidance from the Patch Gazette newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

Which versions of PHPNuxBill are affected by CVE-2026-108107?

All versions of PHPNuxBill through 2025.3.20 are affected by this vulnerability.

Is authentication required to exploit this SQL injection flaw?

No, the vulnerability is unauthenticated, meaning attackers can exploit it without valid user credentials.

What specific parameters can be manipulated to exploit this vulnerability?

Attackers can craft malicious inputs in the username, macAddr, or nasid parameters sent to the radius.php endpoint.

Sources

  1. CVE Program
  2. NVD
PHPNuxBillCVE-2026-108107FreeRADIUSSQL InjectionCWE-89

Related stories

Parameterized Queries Mistakes That Leave Databases Exposed

Most SQL injection flaws persist because developers treat parameterized queries as a magic shield rather than a strict syntax rule with rigid boundaries.