CVE-2026-108108: Improper Authentication in hotspotbilling phpnuxbill
Description
CVE-2026-108108 is an authentication bypass vulnerability in PHPNuxBill up to version 2025.3.20. The flaw exists in the RADIUS CHAP verification process where Password::chap_verify() incorrectly returns true even when the supplied response does not match. This allows attackers who know a valid username to log in with any incorrect password via MikroTik hotspot or PPPoE CHAP, gaining unauthorized network access and consuming the victim's plan.
CVSS v4.0
Score 7.1high
Affected software
hotspotbilling
phpnuxbill
pkg:github/hotspotbilling/phpnuxbillRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
PHPNuxBill versions up to 2025.3.20 contain an authentication bypass vulnerability in the RADIUS CHAP verification mechanism. The function Password::chap_verify() erroneously returns true regardless of the correctness of the supplied response. Consequently, an attacker with knowledge of a valid customer or PPPoE username can authenticate through MikroTik hotspot or PPPoE CHAP using any password, bypassing authentication controls and obtaining network access under the victim's account.
Potential Impact
Successful exploitation allows unauthorized network access by bypassing authentication, enabling attackers to consume the victim customer's network plan. This can lead to unauthorized use of network resources and potential service disruption or financial loss for the affected customer.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the authentication system and monitor for suspicious login attempts involving known usernames.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-10-09T13:44:40.883Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac8fee82cdf04f65660c83a
Added to database: 10/09/2026, 14:49:12 UTC
Last enriched: 10/09/2026, 15:03:38 UTC
Last updated: 10/09/2026, 18:57:32 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.