Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-54237: Wavelog lets anyone run code on server

CVE-2026-54237 · published 4 days ago
Summary

The web version of Wavelog (versions 1.8 through 2.4.1) leaves a setup page open without proper protection, so anyone on the internet can send data that changes files on the server. This could let an attacker read or modify log files and insert their own code, which would then run on the server. Upgrade to Wavelog 2.4.2 or later, or lock down the installation files, to stop this risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
wavelog wavelog >= 1.8, < 2.4.2
Original advisory text
Wavelog: Unauthenticated Remote Code Execution
Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanitized input reaches write_config() and write_configfile() in install/includes/core/core_class.php, allowing a remote unauthenticated attacker to read or write log files and place attacker-controlled content into PHP configuration files. The resulting PHP configuration content can execute on the server. This issue is fixed in version 2.4.2.
Severity
9.9 Critical
Exploitation
EPSS <1%
Type
CWE-94Code Injection
CWE-862Missing Authorization
Timeline
Published17 Sep 2026
Updated21 Sep 2026
First seen17 Sep 2026
Sources
CVE-2026-54237 · MITRE
Track software like this
Free during beta