Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical SQL injection vulnerability within PHPNuxBill's FreeRADIUS REST endpoint, which could allow unauthenticated attackers to access sensitive customer data and credentials. The vulnerability stems from the direct interpolation of request parameters into database queries without proper sanitization, enabling sophisticated data extraction methods.
- Unauthenticated attackers can steal customer data.
- It affects a system handling network authentication.
- Confirm if PHPNuxBill is in use.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can exploit this vulnerability by sending specially crafted requests to the FreeRADIUS REST endpoint. This endpoint is designed to process accounting and authentication information, and it improperly handles user-supplied data within SQL queries. By manipulating parameters like username, MAC address, or NAS ID, an attacker can trigger a time-based blind SQL injection. This could allow them to extract sensitive customer data, including credentials, from the system.
- No authentication required to access.
- Crafted parameters in accounting/authenticate actions.
- Extract customer records and credentials.
Live Threat
Current exploitation, exposure, and threat context
An unauthenticated SQL injection vulnerability in the RADIUS REST endpoint of PHPNuxBill could allow attackers to extract sensitive customer records and credentials. This could occur when an attacker crafts specific username, macAddr, or nasid parameters in accounting or authentication requests. The vulnerability is present in PHPNuxBill through 2025.3.20.
- Customer records and credentials at risk.
- Crafting request parameters could expose data.
- Sensitive information disclosure is possible.
Operational Fix
Recommended remediation, mitigation, and detection steps
The PHPNuxBill RADIUS REST endpoint is likely managed by network or platform teams responsible for access control and billing systems. The first step is to identify all instances of PHPNuxBill, confirm their exposure and business criticality, and assign an owner for remediation planning.
- Network or platform teams should own.
- Verify RADIUS REST endpoint exposure.
- Plan remediation based on confirmed risk.