Skip to content
Threat Feed
critical advisory

Unauthenticated SQL Injection in PHPNuxBill radius.php

PHPNuxBill versions through 2025.3.20 are vulnerable to an unauthenticated time-based blind SQL injection in the radius.php FreeRADIUS REST endpoint, allowing credential and data exfiltration.

CVE search metadata

CVE search record: CVE-2026-108107. Severity: critical. CVSS: 9.8. KEV: no. Product: PHPNuxBill (<= 2025.3.20). Brief: Unauthenticated SQL Injection in PHPNuxBill radius.php. Brief link: https://feed.craftedsignal.io/briefs/2026-10-phpnuxbill-sqli/

What's new

  • 1. added coverage for PHPNuxBill (<= 2025.3.20) Oct 9, 15:33 via nvd
  • 2. added detection rule: Detect Excessive OTP Reset Attempts Oct 9, 15:30 via nvd

PHPNuxBill versions through 2025.3.20 contain a critical unauthenticated SQL injection vulnerability within the radius.php script. The vulnerability exists in the FreeRADIUS REST endpoint, where user-supplied parameters including username, macAddr, and nasid are passed directly into whereRaw() database queries without adequate sanitization. This flaw permits an unauthenticated attacker to execute arbitrary SQL commands against the backend database. By leveraging time-based blind SQL injection techniques, attackers can systematically infer database contents, including sensitive customer records and authentication credentials. This vulnerability represents a high risk to service providers using PHPNuxBill for RADIUS accounting and authentication, as it provides a direct vector for unauthorized data extraction.

Impact

Successful exploitation allows unauthenticated remote attackers to extract the entire customer database, including usernames, passwords, and billing information. This results in complete loss of confidentiality regarding subscriber data and potential compromise of downstream network access credentials managed by the RADIUS server.

Recommendation

Prioritize the identification and patching of all internet-facing instances of PHPNuxBill. Ensure all instances are updated beyond version 2025.3.20 to mitigate CVE-2026-108107.

  • Audit web server access logs for anomalous payloads containing SQL keywords (e.g., SLEEP, BENCHMARK, WAITFOR, or UNION SELECT) targeting the radius.php endpoint.
  • If patching is not immediately feasible, restrict access to the radius.php endpoint at the network or web application firewall level to known-trusted RADIUS infrastructure IPs only.

Immediate actions

Patch PHPNuxBill to version > 2025.3.20

IT Operations 24h

Deploy Sigma detection rule to monitor for SQL injection attempts against radius.php

Detection Engineering 24h

Mitigations

Restrict access to radius.php via firewall or WAF if immediate patching is not possible

immediate IT Operations

CVE-2026-108107

Detection coverage 2

Detect CVE-2026-108107 - Unauthenticated SQL Injection in radius.php

critical

Detects potential time-based blind SQL injection attempts targeting the PHPNuxBill radius.php endpoint via accounting or authentication parameters

sigma tactics: exfiltration, initial_access techniques: T1190 sources: webserver

Detect Excessive OTP Reset Attempts

high

Detects potential brute-force attempts against the password reset flow by monitoring high volumes of POST requests to system/controllers/forgot.php from the same source.

sigma tactics: initial_access techniques: T1110.001 sources: webserver

Detection queries are available on the platform. Get full rules →