Description


PHPNuxBill through 2025.3.20 contains an authentication bypass vulnerability in RADIUS CHAP verification because Password::chap_verify() returns true when the supplied response does not match. Attackers who know a valid customer or PPPoE username can log in through MikroTik hotspot or PPPoE CHAP with any incorrect password to obtain network access and consume that customer's plan.

Related CPE's


Could not find any relations

Weaknesses



CWE-287

CVSS impact metrics


CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

7.1 · High

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-09T15:17:11.887Z

3 hours ago

Last modified

2026-10-09T16:45:01.980Z

1 hour ago