SECURITYCRITICALCVE-2026-108107

CVE-2026-108107: Unauthenticated SQL Injection in PHPNuxBill's radius.php

PHPNuxBill ≤ 2025.3.20 lets unauthenticated attackers extract customer records via blind SQLi in its FreeRADIUS REST endpoint (CVSS 9.8).

Dylan H.

Security Team

October 10, 2026
6 min read
CVE-2026-108107: Unauthenticated SQL Injection in PHPNuxBill's radius.php

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • hotspotbilling/phpnuxbill — all versions through 2025.3.20

Overview

A critical, unauthenticated SQL injection vulnerability, tracked as CVE-2026-108107, has been disclosed in PHPNuxBill, an open-source PHP billing and user-management platform widely used by ISPs and WiFi hotspot operators running MikroTik hardware with a FreeRADIUS backend for authentication, authorization, and accounting (AAA).

The flaw lives in radius.php, PHPNuxBill's FreeRADIUS REST endpoint, which interpolates request parameters directly into Laravel-style whereRaw() database queries without parameterization or type enforcement. An attacker needs no credentials at all — they can send crafted username, macAddr, or nasid parameters to the endpoint's accounting or authenticate actions and extract customer records and credentials via time-based blind SQL injection. NVD published the record on 2026-10-09 with a CVSS 3.1 score of 9.8 (Critical), and CISA, acting as coordinator, scored exploitation as already having a public proof of concept.


Technical Details

FieldValue
CVE IDCVE-2026-108107
CVSS 3.1 Score9.8 (Critical) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 4.0 Score9.3 (Critical) — CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-89 — SQL Injection
Attack VectorNetwork — unauthenticated REST endpoint
Privileges RequiredNone
User InteractionNone
Affected Componentradius.php, accounting and authenticate actions
Vulnerable Coderadius.php, line 277 (v2025.3.13)
GHSAGHSA-q8ch-r8cv-q579
Fixed VersionNone published at time of writing — see Mitigation
Discovered By@kitu232, via GitHub Security Advisories
CISA SSVCExploitation: PoC · Automatable: Yes · Technical Impact: Total

How It Works

PHPNuxBill exposes radius.php so that FreeRADIUS can call back into the billing application for accounting and authentication decisions during a subscriber's hotspot or PPPoE session. The helper functions that read incoming request parameters in this file only trim whitespace — they do not parameterize the resulting SQL or enforce a strict type on fields like username, macAddr, or nasid before passing them into whereRaw() queries.

Because the FreeRADIUS endpoint is designed to be called without a user session (it authenticates the network session, not an admin), there is no authentication gate in front of the vulnerable code at all. A publicly documented proof of concept demonstrates the issue with a time-based blind payload:

# Baseline request (normal response time, ~0.43s)
POST /radius.php?action=accounting
username=victim&macAddr=a&nasid=b

# Injected payload (response delayed to ~5.77s)
POST /radius.php?action=accounting
username=victim' OR SLEEP(5)%23&macAddr=a&nasid=b

The ~5-second delay introduced by the injected SLEEP(5) confirms the payload executes against the backend database, even though the HTTP response still returns a generic success message — the hallmark of blind SQL injection, where data is extracted indirectly (via timing or boolean differences) rather than reflected in the response body.


Impact Assessment

Impact AreaDescription
ConfidentialityHigh — customer records and stored credentials can be extracted from the billing database
IntegrityHigh — depending on database permissions, blind SQLi primitives can sometimes be escalated to writes
AvailabilityHigh — time-based payloads can be abused to degrade database performance; full compromise can disrupt billing/AAA operations
Authentication RequiredNone — the endpoint is reachable by design, for FreeRADIUS callbacks
AutomatableYes, per CISA's SSVC scoring — straightforward to script against exposed instances

Who Is At Risk

  • ISPs and hotspot/PPPoE operators running PHPNuxBill through 2025.3.20 with the FreeRADIUS REST integration enabled
  • Any deployment where radius.php is reachable from outside a trusted management network — which is the normal configuration, since FreeRADIUS needs to reach it
  • Operators who assume FreeRADIUS-facing endpoints are implicitly protected because "only the RADIUS server calls them" — the endpoint accepts any HTTP request matching its expected parameters, not just ones that originate from FreeRADIUS

Attack Chain

  1. Reconnaissance — Attacker identifies a PHPNuxBill instance with its radius.php endpoint reachable (default integration pattern for any FreeRADIUS-backed deployment).
  2. Unauthenticated request — Attacker sends a crafted POST to radius.php?action=accounting (or authenticate), injecting a payload into username, macAddr, or nasid.
  3. Blind extraction — Using time-based (SLEEP()) or boolean-based techniques, the attacker incrementally extracts database contents — customer names, credentials, balances, session records — one bit or character at a time.
  4. Downstream abuse — Extracted customer credentials can be reused for account takeover, fraud, or lateral movement into the operator's broader billing and network infrastructure.

Mitigation

Immediate Actions

  • No patched release is available as of this writing — PHPNuxBill's most recent tagged release is 2025.3.13, with no fix for this issue published in the project's release notes or as a merged pull request. Track GHSA-q8ch-r8cv-q579 for an official fix.
  • If you maintain a fork or can patch locally, convert the vulnerable whereRaw() calls in radius.php to parameterized bindings and validate username, macAddr, and nasid against strict expected formats (e.g., MAC address regex, alphanumeric username pattern) before any query construction.
  • Where immediate code changes aren't feasible, place a WAF rule in front of radius.php to block common SQLi payload patterns (SLEEP(, ' OR , stacked query separators) in the username, macAddr, and nasid parameters.

Detection Opportunities

  • Review web server and application logs for radius.php requests with anomalously long response times (consistent with SLEEP()-based payloads) or SQL metacharacters in request parameters.
  • Watch for a high volume of near-identical requests to the accounting/authenticate actions with incrementally varying payloads — a signature of automated blind-SQLi extraction tooling.

Defence-in-Depth

  • Restrict network access to radius.php to only the IP address(es) of your actual FreeRADIUS server(s) via firewall rules — don't leave it open to the broader internet or LAN.
  • Run the application database user with the minimum privileges required for billing operations, limiting the blast radius if injection does yield write access.
  • Given the lack of a current fix, operators with strict security requirements should weigh migrating off PHPNuxBill, or isolating it behind additional network controls, until a patch lands.

Background

PHPNuxBill is a free, open-source PHP billing and subscriber-management platform built around MikroTik router hardware, commonly paired with a FreeRADIUS server backed by MySQL to handle AAA for hotspot and PPPoE-based ISPs. It's a popular choice for small and mid-sized network operators who need voucher-based billing, auto-renewal, and multi-router support without a commercial billing suite.

The vulnerability was reported by researcher kitu232 through GitHub Security Advisories and coordinated via VulnCheck, which published its own independent advisory alongside the NVD record. As of this writing, the project has not shipped a tagged release addressing the issue, leaving affected operators dependent on local mitigations until an upstream fix is published.


References