CVE-2026-108109 | Hotspotbilling PHPNuxBill up to 2025.3.20 Password Reset forgot.php otp_code improper authentication

SecurityVulns

A vulnerability, which was classified as critical, was found in Hotspotbilling PHPNuxBill up to 2025.3.20. This issue affects some unknown processing of the file system/controllers/forgot.php of the component Password Reset. The manipulation of the argument otp_code results in improper authentication.

This vulnerability is cataloged as CVE-2026-108109. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More