CVE-2026-108107 | HotspotBilling PHPNuxBill up to 2025.3.20 FreeRADIUS REST Endpoint radius.php whereRaw username/macAddr/nasid sql injection

SecurityVulns

A vulnerability has been found in HotspotBilling PHPNuxBill up to 2025.3.20 and classified as critical. Impacted is the function whereRaw of the file radius.php of the component FreeRADIUS REST Endpoint. This manipulation of the argument username/macAddr/nasid causes sql injection.

This vulnerability is registered as CVE-2026-108107. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More