Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-54237: Wavelog lets anyone run code on server
CVE-2026-54237 · published 4 days ago
Summary
The web version of Wavelog (versions 1.8 through 2.4.1) leaves a setup page open without proper protection, so anyone on the internet can send data that changes files on the server. This could let an attacker read or modify log files and insert their own code, which would then run on the server. Upgrade to Wavelog 2.4.2 or later, or lock down the installation files, to stop this risk.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| wavelog | wavelog | >= 1.8, < 2.4.2 |
Original advisory text
Wavelog: Unauthenticated Remote Code Execution
Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanitized input reaches write_config() and write_configfile() in install/includes/core/core_class.php, allowing a remote unauthenticated attacker to read or write log files and place attacker-controlled content into PHP configuration files. The resulting PHP configuration content can execute on the server. This issue is fixed in version 2.4.2.
References
- https://github.com/wavelog/wavelog/security/advisories/GHSA-jxjv-chgm-rh36 Vendor Advisory
- https://github.com/wavelog/wavelog/pull/3228 Patch
- https://github.com/wavelog/wavelog/commit/9661efa86eff4598bd1a7ad8ca4ec60e76b6fb... Patch
- https://github.com/wavelog/wavelog/releases/tag/2.4.2 URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54237... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-54237 Vendor Advisory
Severity
9.9
Critical
Exploitation
EPSS <1%
Type
CWE-94Code Injection
CWE-862Missing Authorization
Timeline
Published17 Sep 2026
Updated21 Sep 2026
First seen17 Sep 2026
Track software like this
Free during beta