CVE-2026-54237EPSS p53.8%
CVE-2026-54237CVE-2026-54237
Description
Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanitized input reaches write_config() and write_configfile() in install/includes/core/core_class.php, allowing a remote unauthenticated attacker to read or write log files and place attacker-controlled content into PHP configuration files. The resulting PHP configuration content can execute on the server. This issue is fixed in version 2.4.2.
Scoring
| EPSS | 0.76% probability of exploitation · percentile 53.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-24 |