CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-108107: phpnuxbill 0 through 2025.3.20

Affected technology

phpnuxbill · 0 through 2025.3.20
hotspotbilling

Description’s affected range: through 2025.3.20

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection. Vendor/CNA’s CVSS 4.0 assessment (base score 9.3/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-89
CVSS 3.1
9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · GitHub Advisory Database
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-108107.html