๐Ÿ” CVE Alert

CVE-2026-108109

CRITICAL 9.1

PHPNuxBill through 2025.3.20 Account Takeover via Brute-Forceable Password Reset Code

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.

CWE CWE-307
Vendor hotspotbilling
Product phpnuxbill
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for hotspotbilling phpnuxbill

Be the first to know when new critical vulnerabilities affecting hotspotbilling phpnuxbill are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

hotspotbilling / phpnuxbill
0 โ‰ค 2025.3.20

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/hotspotbilling/phpnuxbill/security/advisories/GHSA-337r-rrrc-r559 github.com: https://github.com/hotspotbilling/phpnuxbill/commit/c3c2a92d468af91136d747b75142ed72f10320cc github.com: https://github.com/hotspotbilling/phpnuxbill/blob/2025.3.13/system/controllers/forgot.php#L41 github.com: https://github.com/hotspotbilling/phpnuxbill vulncheck.com: https://www.vulncheck.com/advisories/phpnuxbill-through-2025.3.20-account-takeover-via-brute-forceable-password-reset-code

Credits

tonghuaroot ๐Ÿ” leediay153 from Viettel Post