Overview
A critical, unauthenticated SQL injection vulnerability, tracked as CVE-2026-108107, has been disclosed in PHPNuxBill, an open-source PHP billing and user-management platform widely used by ISPs and WiFi hotspot operators running MikroTik hardware with a FreeRADIUS backend for authentication, authorization, and accounting (AAA).
The flaw lives in radius.php, PHPNuxBill's FreeRADIUS REST endpoint, which interpolates request parameters directly into Laravel-style whereRaw() database queries without parameterization or type enforcement. An attacker needs no credentials at all — they can send crafted username, macAddr, or nasid parameters to the endpoint's accounting or authenticate actions and extract customer records and credentials via time-based blind SQL injection. NVD published the record on 2026-10-09 with a CVSS 3.1 score of 9.8 (Critical), and CISA, acting as coordinator, scored exploitation as already having a public proof of concept.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-108107 |
| CVSS 3.1 Score | 9.8 (Critical) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS 4.0 Score | 9.3 (Critical) — CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-89 — SQL Injection |
| Attack Vector | Network — unauthenticated REST endpoint |
| Privileges Required | None |
| User Interaction | None |
| Affected Component | radius.php, accounting and authenticate actions |
| Vulnerable Code | radius.php, line 277 (v2025.3.13) |
| GHSA | GHSA-q8ch-r8cv-q579 |
| Fixed Version | None published at time of writing — see Mitigation |
| Discovered By | @kitu232, via GitHub Security Advisories |
| CISA SSVC | Exploitation: PoC · Automatable: Yes · Technical Impact: Total |
How It Works
PHPNuxBill exposes radius.php so that FreeRADIUS can call back into the billing application for accounting and authentication decisions during a subscriber's hotspot or PPPoE session. The helper functions that read incoming request parameters in this file only trim whitespace — they do not parameterize the resulting SQL or enforce a strict type on fields like username, macAddr, or nasid before passing them into whereRaw() queries.
Because the FreeRADIUS endpoint is designed to be called without a user session (it authenticates the network session, not an admin), there is no authentication gate in front of the vulnerable code at all. A publicly documented proof of concept demonstrates the issue with a time-based blind payload:
# Baseline request (normal response time, ~0.43s)
POST /radius.php?action=accounting
username=victim&macAddr=a&nasid=b
# Injected payload (response delayed to ~5.77s)
POST /radius.php?action=accounting
username=victim' OR SLEEP(5)%23&macAddr=a&nasid=b
The ~5-second delay introduced by the injected SLEEP(5) confirms the payload executes against the backend database, even though the HTTP response still returns a generic success message — the hallmark of blind SQL injection, where data is extracted indirectly (via timing or boolean differences) rather than reflected in the response body.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | High — customer records and stored credentials can be extracted from the billing database |
| Integrity | High — depending on database permissions, blind SQLi primitives can sometimes be escalated to writes |
| Availability | High — time-based payloads can be abused to degrade database performance; full compromise can disrupt billing/AAA operations |
| Authentication Required | None — the endpoint is reachable by design, for FreeRADIUS callbacks |
| Automatable | Yes, per CISA's SSVC scoring — straightforward to script against exposed instances |
Who Is At Risk
- ISPs and hotspot/PPPoE operators running PHPNuxBill through 2025.3.20 with the FreeRADIUS REST integration enabled
- Any deployment where
radius.phpis reachable from outside a trusted management network — which is the normal configuration, since FreeRADIUS needs to reach it - Operators who assume FreeRADIUS-facing endpoints are implicitly protected because "only the RADIUS server calls them" — the endpoint accepts any HTTP request matching its expected parameters, not just ones that originate from FreeRADIUS
Attack Chain
- Reconnaissance — Attacker identifies a PHPNuxBill instance with its
radius.phpendpoint reachable (default integration pattern for any FreeRADIUS-backed deployment). - Unauthenticated request — Attacker sends a crafted
POSTtoradius.php?action=accounting(orauthenticate), injecting a payload intousername,macAddr, ornasid. - Blind extraction — Using time-based (
SLEEP()) or boolean-based techniques, the attacker incrementally extracts database contents — customer names, credentials, balances, session records — one bit or character at a time. - Downstream abuse — Extracted customer credentials can be reused for account takeover, fraud, or lateral movement into the operator's broader billing and network infrastructure.
Mitigation
Immediate Actions
- No patched release is available as of this writing — PHPNuxBill's most recent tagged release is 2025.3.13, with no fix for this issue published in the project's release notes or as a merged pull request. Track GHSA-q8ch-r8cv-q579 for an official fix.
- If you maintain a fork or can patch locally, convert the vulnerable
whereRaw()calls inradius.phpto parameterized bindings and validateusername,macAddr, andnasidagainst strict expected formats (e.g., MAC address regex, alphanumeric username pattern) before any query construction. - Where immediate code changes aren't feasible, place a WAF rule in front of
radius.phpto block common SQLi payload patterns (SLEEP(,' OR, stacked query separators) in theusername,macAddr, andnasidparameters.
Detection Opportunities
- Review web server and application logs for
radius.phprequests with anomalously long response times (consistent withSLEEP()-based payloads) or SQL metacharacters in request parameters. - Watch for a high volume of near-identical requests to the
accounting/authenticateactions with incrementally varying payloads — a signature of automated blind-SQLi extraction tooling.
Defence-in-Depth
- Restrict network access to
radius.phpto only the IP address(es) of your actual FreeRADIUS server(s) via firewall rules — don't leave it open to the broader internet or LAN. - Run the application database user with the minimum privileges required for billing operations, limiting the blast radius if injection does yield write access.
- Given the lack of a current fix, operators with strict security requirements should weigh migrating off PHPNuxBill, or isolating it behind additional network controls, until a patch lands.
Background
PHPNuxBill is a free, open-source PHP billing and subscriber-management platform built around MikroTik router hardware, commonly paired with a FreeRADIUS server backed by MySQL to handle AAA for hotspot and PPPoE-based ISPs. It's a popular choice for small and mid-sized network operators who need voucher-based billing, auto-renewal, and multi-router support without a commercial billing suite.
The vulnerability was reported by researcher kitu232 through GitHub Security Advisories and coordinated via VulnCheck, which published its own independent advisory alongside the NVD record. As of this writing, the project has not shipped a tagged release addressing the issue, leaving affected operators dependent on local mitigations until an upstream fix is published.