๐Ÿ” CVE Alert

CVE-2026-54237

UNKNOWN 0.0

Wavelog: Unauthenticated Remote Code Execution

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanitized input reaches write_config() and write_configfile() in install/includes/core/core_class.php, allowing a remote unauthenticated attacker to read or write log files and place attacker-controlled content into PHP configuration files. The resulting PHP configuration content can execute on the server. This issue is fixed in version 2.4.2.

CWE CWE-94 CWE-862
Vendor wavelog
Product wavelog
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for wavelog wavelog

Be the first to know when new unknown vulnerabilities affecting wavelog wavelog are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

wavelog / wavelog
>= 1.8, < 2.4.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/wavelog/wavelog/security/advisories/GHSA-jxjv-chgm-rh36 github.com: https://github.com/wavelog/wavelog/pull/3228 github.com: https://github.com/wavelog/wavelog/commit/9661efa86eff4598bd1a7ad8ca4ec60e76b6fb25 github.com: https://github.com/wavelog/wavelog/releases/tag/2.4.2