CVE-2026-108108: PHPNuxBill through 2025.3.20 CHAP Authentication Bypass via Password::chap_verify()
PHPNuxBill through 2025.3.20 contains an authentication bypass vulnerability in RADIUS CHAP verification because Password::chapverify() returns true when the supplied response does not match. Attackers who know a valid customer or PPPoE username can log in through MikroTik hotspot or PPPoE CHAP with any incorrect password to obtain network access and consume that customer's plan.
Affected Software
Event History
Frequently Asked Questions
What access or information does an attacker need to exploit this?
The attacker needs to know a valid customer or PPPoE username. No valid password, prior authentication, or user interaction is required.
Which login paths are exposed?
The issue affects RADIUS CHAP verification used for MikroTik hotspot or PPPoE CHAP logins. An attacker can use an incorrect password with a valid username to obtain network access under that customer's plan.
What is the practical impact of successful exploitation?
A successful attacker can authenticate as the identified customer and consume that customer's network plan. The provided data does not indicate impacts beyond unauthorized network access and plan consumption.