The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Rapid7 and NVD confirm CVE-2026-108108, an auth bypass in PHPNuxBill through 2025.3.20 allowing CHAP bypass with any password for valid usernames.

Sourcing
1source

via NVD

NVD · track record
50Stories
100%Verified
2730d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/PHPNuxBill through 2025.3.20 hit by CVE-2026-108108 auth bypass
VERIFIEDBy Xavier Rivera· ·1 min read

PHPNuxBill through 2025.3.20 hit by CVE-2026-108108 auth bypass

PHPNuxBill through 2025.3.20 is affected by CVE-2026-108108, a CVSS 7.1 authentication bypass in RADIUS CHAP verification. Attackers with a valid username can gain network access and consume customer plans using any password.

Source:NVD
Post
PHPNuxBill through 2025.3.20 hit by CVE-2026-108108 auth bypass
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

PHPNuxBill through version 2025.3.20 contains an authentication bypass tracked as CVE-2026-108108 with CVSS score 7.1. Attackers who know a valid username can authenticate via MikroTik hotspot or PPPoE CHAP using any wrong password. The flaw in Password::chap_verify() grants network access and lets attackers consume the targeted customer's plan on adjacent networks.

PHPNuxBill through version 2025.3.20 contains an authentication bypass vulnerability tracked as CVE-2026-108108 with a CVSS score of 7.1 rated HIGH.

The flaw allows unauthorized network access. Attackers who know a valid customer or PPPoE username can authenticate through MikroTik hotspot or PPPoE CHAP using any incorrect password. The vulnerability stems from Password::chap_verify() returning true even when the supplied response does not match the expected value.
Attackers who know a valid customer or PPPoE username can authenticate through MikroTik hotspot or PPPoE CHAP using any incorrect password.

Successful exploitation grants network access and lets the attacker consume the targeted customer's plan.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
Reach and impact remain network-local. The CVSS vector indicates an adjacent network attack with low complexity, no privileges required, and no user interaction. Confidentiality impact is limited while integrity impact is high and availability impact is none.
The vulnerability stems from Password::chap_verify() returning true even when the supplied response does not match the expected value.
Versions through 2025.3.20 are affected. The issue was recorded in the National Vulnerability Database on the same day the advisory references were published. The GitHub repository and security advisory provide the primary references for the flaw.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Users should review the linked advisory. The project maintains its code at the hotspotbilling/phpnuxbill repository with the affected function located in system/autoload/Password.php.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
securityvulnerabilityphpnuxbill
More fromNVD
  • Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Tech · 17h
  • Critical CVE-2026-77900 Hits Microsoft Azure App Service for Linux

    Tech · 17h
  • Critical CVE-2026-88131 hits Microsoft Dataverse with remote code execution

    Tech · 17h
More inTech
  • Modern Warfare 4 DMZ Early Access Opens October 20

    Tech · 1h
  • GlobalFoundries signs $2B TSMC deal for US silicon interposers

    Tech · 14h
  • SpaceX agrees to buy 800 MHz spectrum for Starlink Mobile

    Tech · 17h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    IBM Security Verify Access: 4 more vulnerabilities disclosed

    IBM has disclosed four more flaws in Security Verify Access and Verify Identity Access, including a code execution bug it rates critical at 9.1 (NVD: 8.8). Versions 10.0 to 10.0.9.2 and 11.0 to 11.0.3 are affected. IBM says to upgrade to 10.0.9.3 or 11.0.3.1.

  • Tech· 

    Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Microsoft has disclosed CVE-2026-83947, a CVSS 7.7 HIGH spoofing vulnerability in Azure Event Grid caused by missing authorization. Microsoft says it has already fully mitigated the cloud-service flaw and customers have nothing to do.

  • Tech· 

    Critical CVE-2026-77900 Hits Microsoft Azure App Service for Linux

    A critical vulnerability CVE-2026-77900 affects Microsoft Azure App Service for Linux with a CVSS score of 9.8. The flaw allows an unauthenticated attacker to execute code over the network. Microsoft says it has already fully mitigated the flaw; no customer action is needed.

  • Tech· 

    Critical CVE-2026-88131 hits Microsoft Dataverse with remote code execution

    Microsoft Dataverse is affected by critical vulnerability CVE-2026-88131, which allows remote code execution. The flaw scores 9.8 on CVSS; Microsoft says it has already fully mitigated it and customers have nothing to patch.

  • Tech· 

    Critical CVE-2026-16823 hits IBM Security Verify Access

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 contain critical authentication bypass flaw CVE-2026-16823. The NVD rates it 9.1 and warns of remote exploitation without credentials.