Mmastodon TechnologyCybersecurity first seen 16 h ago, last 16 h ago, peak #11
PHPNuxBill hit by two unpatched vulnerabilities
Original: π΄ PHPNuxBill β 2 CVEs, no patch CVE-2026-108107 (9.8): unauth SQL injection in radius.php β request params interpolated
Security researchers report two unpatched vulnerabilities in PHPNuxBill, a billing system used by internet service providers. CVE-2026-108107, rated 9.8, is an unauthenticated SQL injection in radius.php that allows full database reads without credentials. CVE-2026-108108, rated 7.1, is a CHAP authentication bypass that lets anyone on the network authenticate with a wrong password. No patches are available yet, leaving exposed installations at immediate risk.
Why now: Both flaws are critical and unpatched, so admins running PHPNuxBill are scrambling to assess exposure.
Evidence
- π΄ PHPNuxBill β 2 CVEs, no patch CVE-2026-108107 (9.8): unauth SQL injection in radius.php β request params interpolated into whereRaw() β full DB read, no credentials required. CVE-2026-108108 (7.1): CHAP bypass β chap_verify() returns true on mismatch β network access with anyβ¦ Β· threataft@infosec.exchange Β· 2
API: https://socialmediatrends-api.osmike.com/v1/trends/1684820