External risk intelligence

PHPNuxBill Unauthenticated SQL Injection in RADIUS Endpoint.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-108107

The vulnerability resides in a RADIUS REST endpoint designed to handle network accounting and authentication requests. RADIUS and its associated REST interfaces are typically exposed to receive traffic from network access servers, making them intentionally internet-facing or edge-reachable services in standard deployments.

SQL Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical SQL injection vulnerability within PHPNuxBill's FreeRADIUS REST endpoint, which could allow unauthenticated attackers to access sensitive customer data and credentials. The vulnerability stems from the direct interpolation of request parameters into database queries without proper sanitization, enabling sophisticated data extraction methods.

  • Unauthenticated attackers can steal customer data.
  • It affects a system handling network authentication.
  • Confirm if PHPNuxBill is in use.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending specially crafted requests to the FreeRADIUS REST endpoint. This endpoint is designed to process accounting and authentication information, and it improperly handles user-supplied data within SQL queries. By manipulating parameters like username, MAC address, or NAS ID, an attacker can trigger a time-based blind SQL injection. This could allow them to extract sensitive customer data, including credentials, from the system.

  • No authentication required to access.
  • Crafted parameters in accounting/authenticate actions.
  • Extract customer records and credentials.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated SQL injection vulnerability in the RADIUS REST endpoint of PHPNuxBill could allow attackers to extract sensitive customer records and credentials. This could occur when an attacker crafts specific username, macAddr, or nasid parameters in accounting or authentication requests. The vulnerability is present in PHPNuxBill through 2025.3.20.

  • Customer records and credentials at risk.
  • Crafting request parameters could expose data.
  • Sensitive information disclosure is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

The PHPNuxBill RADIUS REST endpoint is likely managed by network or platform teams responsible for access control and billing systems. The first step is to identify all instances of PHPNuxBill, confirm their exposure and business criticality, and assign an owner for remediation planning.

  • Network or platform teams should own.
  • Verify RADIUS REST endpoint exposure.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is PHPNuxBill and how is it used?

PHPNuxBill is an open-source billing and management platform designed for internet service providers and hotspot operators. It handles core business functions like network authentication, user account management, and accounting. By integrating with FreeRADIUS, it acts as a central hub that manages how users connect to a network and ensures they are correctly billed for their service usage.

What does CVE-2026-108107 mean for the software?

This vulnerability is an SQL injection, which falls under the CWE-89 weakness class. It occurs because the software fails to sanitize user-provided data before including it in database commands. Because the FreeRADIUS REST endpoint directly inserts input into database queries, an attacker can manipulate these commands to interact with the underlying database without needing an account or any prior authorization.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending specially crafted web requests to the FreeRADIUS REST endpoint used by the application. By injecting malicious code into specific parameters—such as the username, MAC address, or network access server ID—they can force the database to reveal information through a time-based blind SQL injection. Requests that do not include these specific, manipulated parameters in the accounting or authentication actions will not trigger the vulnerability.

Is my PHPNuxBill instance likely reachable by attackers?

According to Halo Surface Signal, this vulnerability is very likely to be reachable because it exists in a REST endpoint designed to receive traffic from network access servers. These interfaces are often configured to be edge-reachable or internet-facing to communicate with remote infrastructure, which unfortunately increases the likelihood that an external attacker could attempt to exploit the endpoint.

What should I do first to manage this risk?

Begin by creating an inventory of all PHPNuxBill deployments in your environment to determine where the software is running. Once identified, verify if the specific FreeRADIUS REST endpoint is active and exposed to the network. Assign a technical owner to coordinate with your network or platform teams to prioritize these instances for security updates and limit unnecessary external access to the endpoint.

References