CVE-2026-108108: PHPNuxBill through 2025.3.20 CHAP Authentication Bypass via Password::chap_verify()

Published Oct 9, 2026
·
Updated

PHPNuxBill through 2025.3.20 contains an authentication bypass vulnerability in RADIUS CHAP verification because Password::chapverify() returns true when the supplied response does not match. Attackers who know a valid customer or PPPoE username can log in through MikroTik hotspot or PPPoE CHAP with any incorrect password to obtain network access and consume that customer's plan.

Affected Software

1 affected component
PHPNuxBill PHPNuxBill<=2025.3.20

Event History

Oct 9, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What access or information does an attacker need to exploit this?

The attacker needs to know a valid customer or PPPoE username. No valid password, prior authentication, or user interaction is required.

2

Which login paths are exposed?

The issue affects RADIUS CHAP verification used for MikroTik hotspot or PPPoE CHAP logins. An attacker can use an incorrect password with a valid username to obtain network access under that customer's plan.

3

What is the practical impact of successful exploitation?

A successful attacker can authenticate as the identified customer and consume that customer's network plan. The provided data does not indicate impacts beyond unauthorized network access and plan consumption.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203