CVE Watchtower

← Back to CVE List

CVE-2026-54237NVD

Description

Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanitized input reaches write_config() and write_configfile() in install/includes/core/core_class.php, allowing a remote unauthenticated attacker to read or write log files and place attacker-controlled content into PHP configuration files. The resulting PHP configuration content can execute on the server. This issue is fixed in version 2.4.2.
Severity Level
CRITICAL (9.3)
Published Date
17/09/2026
Last Modified
18/09/2026
Exploitation Status
????
EPSS Score
0.56% (percentile 45.3%)

CVSS Base Metrics

CVSS v4 (4.0)
CRITICAL 9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Weaknesses (CWE)

CWE-94 - CWE-94: Improper Control of Generation of Code ('Code Injection')CWE-862 - CWE-862: Missing Authorization

Affected & Patched Versions

ProductAffected VersionsPatched Version
wavelog wavelog>= 1.8, < 2.4.2N/A
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.