PHPNuxBill 2025.3.20 及之前版本在 RADIUS CHAP 验证中存在身份认证绕过漏洞。具体而言,当提供的响应与预期不匹配时, 函数仍返回 true,从而导致身份验证被绕过。攻击者如果知道有效的客户用户名或 PPPoE 用户名,可以通过 MikroTik 热点或 PPPoE CHAP 使用任意错误的密码登录,从而获取网络访问权限,并滥用该客户账户的资源。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| hotspotbilling | phpnuxbill | ≤ 2025.3.20 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| hotspotbilling | phpnuxbill | 0 ~ 2025.3.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108107 | 9.8 CRITICAL | PHPNuxBill through 2025.3.20 Unauthenticated SQL Injection via radius.php |
| CVE-2026-108109 | 9.1 CRITICAL | PHPNuxBill through 2025.3.20 Account Takeover via Brute-Forceable Password Reset Code |
No comments yet