Web-Based Amateur Radio Logging Software Vulnerability in Wavelog
CVE-2026-54237
9.3CRITICAL
What is CVE-2026-54237?
Wavelog is a web-based amateur radio logging software that suffers from improper access control vulnerabilities. It exposes critical files such as /install/ajax.php and /install/includes/interface_assets/triggers.php after installation, without adequate permission checks. This lack of security allows an unauthenticated remote attacker to manipulate the logging files and potentially inject malicious content into the PHP configuration files using unsanitized input. The issue has been addressed in version 2.4.2, making it crucial for users running earlier versions to upgrade promptly.
Affected Version(s)
wavelog >= 1.8, < 2.4.2
