CRITICAL
wavelog
CVE published 2026-09-17
CVE-2026-54237
CVE-2026-54237 is a critical vulnerability in Wavelog, a web-based amateur radio logging software. The vulnerability exists in versions 1.8 through 2.4.2 and allows a remote unauthenticated attacker to read or write log files and place attacker-controlled content into PHP configuration files, potentially leading to code execution on the server. The issue is fixed in version 2.4.2.