Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54237— Wavelog: Unauthenticated Remote Code Execution

Quick assessment

Affected
wavelog wavelog
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Wavelog 是一款基于 Web 的业余无线电日志记录软件。在 1.8 至 2.4.2 版本中,Wavelog 在安装完成后仍未对 和 实施安装锁或权限检查,导致这些文件依然可被访问。未经验证的用户输入会传入 中的 和 函数,使得远程未认证攻击者能够读取或写入日志文件,并将攻击者控制的内容写入 PHP 配置文件中。由此生成的 PHP 配置内容可在服务器上执行代码。该问题已在 2.4.2 版本中修复。

CVSS 9.3 · Critical EPSS 0.56% · P45
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54237

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Wavelog: Unauthenticated Remote Code Execution
Source: CVE Program / CVE List V5
Vulnerability Description
Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanitized input reaches write_config() and write_configfile() in install/includes/core/core_class.php, allowing a remote unauthenticated attacker to read or write log files and place attacker-controlled content into PHP configuration files. The resulting PHP configuration content can execute on the server. This issue is fixed in version 2.4.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wavelog wavelog >= 1.8, < 2.4.2 -

II. Public POCs for CVE-2026-54237

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54237

登录查看更多情报信息。

Patches & Fixes for CVE-2026-54237 (1)

Vendor Advisories for CVE-2026-54237 (1)

Vendor Pages for CVE-2026-54237 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54237

No comments yet


Leave a comment