Unauthenticated SQL Injection in PHPNuxBill radius.php
PHPNuxBill versions through 2025.3.20 are vulnerable to an unauthenticated time-based blind SQL injection in the radius.php FreeRADIUS REST endpoint, allowing credential and data exfiltration.
CVE search metadata
CVE search record: CVE-2026-108107. Severity: critical. CVSS: 9.8. KEV: no. Product: PHPNuxBill (<= 2025.3.20). Brief: Unauthenticated SQL Injection in PHPNuxBill radius.php. Brief link: https://feed.craftedsignal.io/briefs/2026-10-phpnuxbill-sqli/
What's new
PHPNuxBill versions through 2025.3.20 contain a critical unauthenticated SQL injection vulnerability within the radius.php script. The vulnerability exists in the FreeRADIUS REST endpoint, where user-supplied parameters including username, macAddr, and nasid are passed directly into whereRaw() database queries without adequate sanitization. This flaw permits an unauthenticated attacker to execute arbitrary SQL commands against the backend database. By leveraging time-based blind SQL injection techniques, attackers can systematically infer database contents, including sensitive customer records and authentication credentials. This vulnerability represents a high risk to service providers using PHPNuxBill for RADIUS accounting and authentication, as it provides a direct vector for unauthorized data extraction.
Impact
Successful exploitation allows unauthenticated remote attackers to extract the entire customer database, including usernames, passwords, and billing information. This results in complete loss of confidentiality regarding subscriber data and potential compromise of downstream network access credentials managed by the RADIUS server.
Recommendation
Prioritize the identification and patching of all internet-facing instances of PHPNuxBill. Ensure all instances are updated beyond version 2025.3.20 to mitigate CVE-2026-108107.
- Audit web server access logs for anomalous payloads containing SQL keywords (e.g., SLEEP, BENCHMARK, WAITFOR, or UNION SELECT) targeting the radius.php endpoint.
- If patching is not immediately feasible, restrict access to the radius.php endpoint at the network or web application firewall level to known-trusted RADIUS infrastructure IPs only.
Immediate actions
Patch PHPNuxBill to version > 2025.3.20
Deploy Sigma detection rule to monitor for SQL injection attempts against radius.php
Mitigations
Restrict access to radius.php via firewall or WAF if immediate patching is not possible
CVE-2026-108107
Detection coverage 2
Detect CVE-2026-108107 - Unauthenticated SQL Injection in radius.php
criticalDetects potential time-based blind SQL injection attempts targeting the PHPNuxBill radius.php endpoint via accounting or authentication parameters
Detect Excessive OTP Reset Attempts
highDetects potential brute-force attempts against the password reset flow by monitoring high volumes of POST requests to system/controllers/forgot.php from the same source.
Detection queries are available on the platform. Get full rules →