Get real-time updates on Telegram
Verified
CVE-2026-108107: phpnuxbill 0 through 2025.3.20
Affected technology
phpnuxbill · 0 through 2025.3.20
hotspotbilling
Description’s affected range: through 2025.3.20
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required
What an attacker can do
Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection. Vendor/CNA’s CVSS 4.0 assessment (base score 9.3/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-89
- CVSS 3.1
- 9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · GitHub Advisory Database
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-09 22:06:25.045838+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-09 21:08:49.498434+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-108107.html