CVE-2026-54237

Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanitized input reaches write_config() and write_configfile() in install/includes/core/core_class.php, allowing a remote unauthenticated attacker to read or write log files and place attacker-controlled content into PHP configuration files. The resulting PHP configuration content can execute on the server. This issue is fixed in version 2.4.2.

  • Published Sep 17, 2026
  • CVSS 9.3 critical
  • 0.8% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-54237 at the National Vulnerability Database