CVE-2026-54237: Wavelog

Critical severity, CVSS 9.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanitized input reaches write_config() and write_configfile() in install/includes/core/core_class.php, allowing a remote unauthenticated attacker to read or write log files and place attacker-controlled content into PHP configuration files. The resulting PHP configuration content can execute on the server. This issue is fixed in version 2.4.2.

Affected products

  • Wavelog Wavelog: from 1.8, before 2.4.2 (fixed in 2.4.2)

Published 2026-09-17. Last modified 2026-09-24.