On this page
CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
Weakness Summary
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
- Canonical source: MITRE CWE-77 (opens in a new tab)
- Published Atomicorp CVE observations: 140
- Distinct affected products in those observations: 79
- Active Atomicorp rules associated with this weakness: 39
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2026-72869 | Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE | dokploy | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2012-1823 | PHP CGI v5.3.12/5.4.2 Remote Code Execution | php | Attack Blocked by Atomicorp | 340165 , 378491 |
| CVE-2014-1203 | Eyou E-Mail <3.6 - Remote Code Execution | eyou | Attack Blocked by Atomicorp | 340023 , 341245 , 344360 , 344361 , 344363 , 344370 |
| CVE-2016-10108 | Western Digital MyCloud NAS - Command Injection | mycloud nas | Attack Blocked by Atomicorp | 344364 , 344366 |
| CVE-2016-1555 | NETGEAR WNAP320 Access Point Firmware - Remote Command Injection | wnap320 firmware | Attack Blocked by Atomicorp | 340014 , 344364 , 344366 |
| CVE-2016-9682 | Sonicwall Secure Remote Access 8.1.0.2-14sv - Command Injection | sonicwall secure remote access server | Attack Blocked by Atomicorp | 390727 , 392301 , 392648 |
| CVE-2020-13117 | Wavlink Multiple AP - Remote Command Injection | wn575a4 | Attack Blocked by Atomicorp | 340014 , 344364 , 344366 , 344370 |
| CVE-2021-1498 | Cisco HyperFlex HX Data Platform - Remote Command Execution | hyperflex hx data platform | Attack Blocked by Atomicorp | 340014 , 344364 , 344366 , 344370 |
| CVE-2022-36553 | Hytec Inter HWL-2511-SS - Remote Command Execution | hwl-2511-ss firmware | Attack Blocked by Atomicorp | 344360 , 347009 , 390904 |
| CVE-2022-40881 | SolarView 6.00 - Remote Command Execution | solarview compact | Attack Blocked by Atomicorp | 340029 , 344360 , 344370 , 393655 |
| CVE-2023-20887 | VMware VRealize Network Insight - Remote Code Execution | vrealize network insight | Attack Blocked by Atomicorp | 391213 |
| CVE-2023-23333 | SolarView Compact 6.00 - OS Command Injection | solarview compact firmware | Attack Blocked by Atomicorp | 344361 , 344363 , 390613 , 390614 |
| CVE-2023-30258 | MagnusBilling - Remote Code Execution | magnusbilling | Attack Blocked by Atomicorp | 344363 , 344364 , 344366 |
| CVE-2023-33831 | FUXA - Unauthenticated Remote Code Execution | fuxa | Attack Blocked by Atomicorp | 340095 , 344370 , 345240 , 380026 |
| CVE-2023-34960 | Chamilo Command Injection | chamilo | Attack Blocked by Atomicorp | 341245 , 344360 , 344361 , 344363 , 344370 |
| CVE-2023-3710 | Honeywell PM43 Printers - Command Injection | pm43 firmware | Attack Blocked by Atomicorp | 344361 , 344363 |
| CVE-2023-37679 | NextGen Mirth Connect - Remote Code Execution | mirth connect | Attack Blocked by Atomicorp | 344363 |
| CVE-2023-45852 | Viessmann Vitogate 300 - Remote Code Execution | vitogate 300 firmware | Attack Blocked by Atomicorp | 344360 , 344361 , 344363 |
| CVE-2023-46574 | TOTOLINK A3700R - Command Injection | a3700r firmware | Attack Blocked by Atomicorp | 392301 , 392648 |
| CVE-2023-50917 | MajorDoMo thumb.php - OS Command Injection | majordomo | Attack Blocked by Atomicorp | 344363 |
| CVE-2024-22729 | Netis MW5360 V1.0.1.3031 - Command Injection | mw5360 firmware | Attack Blocked by Atomicorp | 392301 |
| CVE-2024-39914 | FOG Project < 1.5.10.34 - Remote Command Execution | fogproject | Attack Blocked by Atomicorp | 344363 |
| CVE-2024-55956 | Cleo Harmony < 5.8.0.24 - File Upload Vulnerability | harmony | Attack Blocked by Atomicorp | 391213 |
| CVE-2025-45985 | Blink Router - Command Injection | bl-wr9000 firmware | Attack Blocked by Atomicorp | 344363 |
| CVE-2026-30623 | LiteLLM 1.18.10 - Command Injection | LiteLLM 1.18.10 | Attack Blocked by Atomicorp | 320009 |
| CVE-2026-34243 | wenxian: Command Injection in GitHub Actions Workflow via issue_comment.body | wenxian | Attack Blocked by Atomicorp | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-35847 | the CheckUils.php file Arbitrary Code Execution Vulnerability | the CheckUils.php file | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-8037 | Progress ADC LoadMaster - Command Injection | connection manager for objectscale | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2024-9264 | Grafana Post-Auth DuckDB - SQL Injection To File Read | grafana | Attack Blocked by Atomicorp | 340016 , 344360 , 344370 |
| CVE-2025-54782 | NestJS DevTools Integration - Remote Code Execution | devtools-integration | Attack Blocked by Atomicorp | 345240 |
| CVE-2026-47670 | DbGate - Remote Code Execution via Dynamic Import Bypass | dbgate | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340149 , 340162 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 345240 , 346755 , 380026 , 393655 |
| CVE-2026-7202 | Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-7203 | Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-7204 | Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9384 | Totolink A8000RU Web Management cstecgi.cgi setDiagnosisCfg os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9385 | Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-9386 | Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9387 | Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9388 | Totolink A8000RU Web Management cstecgi.cgi setScheduleCfg os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9404 | Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9405 | Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9406 | Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9407 | Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9408 | Totolink A8000RU Web Management cstecgi.cgi setStaticDhcpRules os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9432 | Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9433 | Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9434 | Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9435 | Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9436 | Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9454 | Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9455 | Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9456 | Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9457 | Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9458 | Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9475 | Totolink A8000RU Web Management cstecgi.cgi setIpQosRules os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340029 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-9476 | Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9477 | Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9478 | Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injection | A8000RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2014-9118 | ZHONE < S3.0.501 - Multiple Vulnerabilities | znid 2426a firmware | Attack Blocked by Atomicorp | 390726 , 392301 , 392647 , 392648 |
| CVE-2020-15874 | Command Injection | - | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2023-1389 | TP-Link Archer AX21 (AX1800) - Unauthenticated Command Injection | archer-ax21 | Attack Blocked by Atomicorp | 393655 |
| CVE-2022-41800 | F5 BIG-IP Appliance Mode - Command Injection | big-ip access policy manager | Attack Blocked by Atomicorp | 344362 , 344363 |
| CVE-2024-7029 | AVTECH IP Camera - Command Injection | avm1203 firmware | Attack Blocked by Atomicorp | 344363 |
| CVE-2025-4008 | MeteoBridge <= 6.1 - Remote Code Execution | meteobridge vm | Attack Blocked by Atomicorp | 393655 |
| CVE-2026-55182 | LibreNMS: Remote Code Execution by Signal Alert Transportation Module | librenms | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-82692 | D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection | DNS-340L | Attack Blocked by Atomicorp | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-85223 | D-Link DNS-340L CGI dropbox.cgi os command injection | DNS-340L | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-86299 | Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection | RE7000 | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-82690 | D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection | DNS-327L | Attack Blocked by Atomicorp | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-82691 | D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection | DNS-320L | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-85222 | D-Link DNS-340L Add-On Center addon_center.cgi os command injection | DNS-340L | Attack Blocked by Atomicorp | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-85224 | D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection | DNS-320 ShareCenter | Attack Blocked by Atomicorp | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2023-47218 | QNAP QTS and QuTS Hero - OS Command Injection | qts | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2016-3081 | Apache S2-032 Struts - Remote Code Execution | struts | Attack Blocked by Atomicorp | 337209 , 337211 , 344360 , 347009 , 390904 |
| CVE-2021-20167 | Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrun | rax43 firmware | Attack Blocked by Atomicorp | 392301 |
| CVE-2023-34105 | SRS - Command Injection | simple realtime server | Attack Blocked by Atomicorp | 344364 |
| CVE-2026-10870 | Shibby Tomato Web UI rc start_dhcpc os command injection | Tomato | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-10871 | Shibby Tomato Web UI rc start_6rd_tunnel os command injection | Tomato | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-10873 | Shibby Tomato Web UI rstats rstats_path os command injection | Tomato | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-18900 | H3C NX15 Backend RPC esps file.exec os command injection | NX15 | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-19771 | Baicells EG3661M LuCI Web luci os command injection | EG3661M | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2024-38288 | TurboMeeting - Post-Authentication Command Injection | turbomeeting | Attack Blocked by Atomicorp | 344363 , 344370 |
| CVE-2025-29635 | D-Link DIR-823X set_prohibiting - Command Injection | dir-823x firmware | Attack Blocked by Atomicorp | 340014 , 344364 , 344366 |
| CVE-2025-32813 | Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_request | netmri | Attack Blocked by Atomicorp | 393655 |
| CVE-2024-11320 | Pandora v7.0NG.777.3 - Remote Code Execution | pandora fms | Attack Blocked by Atomicorp | 344363 |
| CVE-2024-12987 | DrayTek Vigor - Command Injection | Vigor300B | Attack Blocked by Atomicorp | 347009 , 393655 |
| CVE-2026-11450 | GL.iNet GL-MT3000 Path Normalization dlopen command injection | GL-MT3000 | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-19983 | GL.iNet XE3000 NAS Command Service gl_nas_sys os command injection | A1300 | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2025-55911 | ClipBucket 5.5.2 Build #90 - Server-Side Request Forgery (SSRF) | clipbucket | Attack Blocked by Atomicorp | 340162 , 344370 , 398001 |
| CVE-2026-10214 | zhayujie chatgpt-on-wechat Bash Tool bash.py _get_safety_warning os command injection | chatgpt-on-wechat | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-18641 | Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginC | Operation and Maintenance Security Management System | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-19379 | EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection | ipTIME AX8004M | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-5677 | Totolink A7100RU cstecgi.cgi CsteSystem os command injection | A7100RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5678 | Totolink A7100RU cstecgi.cgi setScheduleCfg os command injection | A7100RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5688 | Totolink A7100RU cstecgi.cgi setDdnsCfg os command injection | A7100RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5689 | Totolink A7100RU cstecgi.cgi setNtpCfg os command injection | A7100RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5690 | Totolink A7100RU cstecgi.cgi setRemoteCfg os command injection | A7100RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5691 | Totolink A7100RU cstecgi.cgi setFirewallType os command injection | A7100RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5692 | Totolink A7100RU cstecgi.cgi setGameSpeedCfg os command injection | A7100RU | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5741 | suvarchal docker-mcp-server HTTP index.ts pull_image os command injection | docker-mcp-server | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5802 | idachev mcp-javadc HTTP os command injection | mcp-javadc | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-7220 | jackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injection | FastlyMCP | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-76761 | chenhg5 cc-connect Management API engine.go shellExecCommand os command injection | cc-connect | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2024-33113 | D-LINK DIR-845L bsc_sms_inbox.php file - Information Disclosure | dir-845l | Attack Blocked by Atomicorp | 390722 |
| CVE-2026-5547 | Tenda AC10 httpd formAddMacfilterRule os command injection | ac10 firmware | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-10279 | hiraishikentaro wezterm-mcp switch_pane/write_to_specific_pane wezterm_executor.ts os command injection | wezterm-mcp | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-11408 | vertex-app vertex Log Viewer Endpoint LogMod.js os command injection | vertex | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-5351 | Trendnet TEW-657BRM setup.cgi add_wps_client os command injection | tew-657brm firmware | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5352 | Trendnet TEW-657BRM setup.cgi edit os command injection | tew-657brm firmware | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5353 | Trendnet TEW-657BRM setup.cgi ping_test os command injection | tew-657brm firmware | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5354 | Trendnet TEW-657BRM setup.cgi vpn_connect os command injection | tew-657brm firmware | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5355 | Trendnet TEW-657BRM setup.cgi vpn_drop os command injection | tew-657brm firmware | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8188 | Wavlink NU516U1 adm.cgi change_wifi_password os command injection | wl-nu516u1 firmware | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8189 | Wavlink NU516U1 adm.cgi wzdrepeater os command injection | wl-nu516u1 firmware | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8190 | Wavlink NU516U1 adm.cgi wan os command injection | wl-nu516u1 firmware | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8191 | Wavlink NU516U1 adm.cgi wifi_region os command injection | wl-nu516u1 firmware | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-8192 | Wavlink NU516U1 adm.cgi wzdap os command injection | wl-nu516u1 firmware | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8227 | Wavlink NU516U1 adm.cgi wzdapMesh os command injection | wl-nu516u1 firmware | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8228 | Wavlink NU516U1 wireless.cgi advance os command injection | wl-nu516u1 firmware | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8229 | Wavlink NU516U1 wireless.cgi WifiBasic os command injection | wl-nu516u1 firmware | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8230 | Wavlink NU516U1 login.cgi sys_login1 os command injection | wl-nu516u1 firmware | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8264 | Tenda AC6 httpd WifiApScan formWifiApScan os command injection | ac6 firmware | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9343 | Edimax EW-7438RPn webs formWpsStart os command injection | EW-7438RPn | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9347 | Edimax EW-7438RPn webs formWizSurvey os command injection | EW-7438RPn | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9424 | Edimax EW-7438RPn Content-Type formWlanMP os command injection | EW-7438RPn | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9511 | Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection | CA750-PoE | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9512 | Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injection | CA750-PoE | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9514 | Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection | CA750-PoE | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9515 | Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection | CA750-PoE | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9531 | Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection | CA750-PoE | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9532 | Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injection | CA750-PoE | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9533 | Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injection | CA750-PoE | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9534 | Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injection | CA750-PoE | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8259 | Tenda AC6 httpd telnet os command injection | ac6 firmware | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8265 | Tenda AC6 httpd getLogFile get_log_file os command injection | ac6 firmware | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-82678 | diem-project diem Administrative Console actions.class.php executeCommand os command injection | diem | Attack Blocked by Atomicorp | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 |
| CVE-2026-82702 | Edimax BR-6214K asp_WlanMP Endpoint wlanMP.asp system os command injection | BR-6214K | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-82703 | Edimax BR-6214K asp_setPing Endpoint ping.asp system os command injection | BR-6214K | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-85040 | ZhongBangKeJi CRMEB Custom Scheduled Task Feature save eval os command injection | CRMEB | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5621 | ChrisChinchilla Vale-MCP HTTP index.ts os command injection | Vale-MCP | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 320009 | Active | disruptive (deny) |
| 330791 | Active | disruptive (deny) |
| 337209 | Active | disruptive (deny) |
| 337211 | Active | disruptive (deny) |
| 340014 | Active | disruptive (deny) |
| 340016 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340029 | Active | disruptive (deny) |
| 340095 | Active | disruptive (deny) |
| 340149 | Active | disruptive (deny) |
| 340152 | Active | disruptive (deny) |
| 340162 | Active | disruptive (deny) |
| 340165 | Active | disruptive (deny) |
| 340193 | Active | disruptive (deny) |
| 341245 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344362 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344364 | Active | disruptive (deny) |
| 344366 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 345240 | Active | disruptive (deny) |
| 346755 | Active | disruptive (deny) |
| 347009 | Active | disruptive (deny) |
| 378491 | Active | disruptive (deny) |
| 380026 | Active | disruptive (deny) |
| 390613 | Active | disruptive (deny) |
| 390614 | Active | disruptive (deny) |
| 390722 | Active | disruptive (deny) |
| 390726 | Active | disruptive (deny) |
| 390727 | Active | disruptive (deny) |
| 390904 | Active | disruptive (deny) |
| 391213 | Active | disruptive (deny) |
| 392301 | Active | disruptive (deny) |
| 392647 | Active | disruptive (deny) |
| 392648 | Active | disruptive (deny) |
| 393655 | Active | disruptive (deny) |
| 398001 | Active | non-disruptive (pass) |
Related MITRE CAPEC Context
MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:
CAPEC-136 (opens in a new tab) , CAPEC-15 (opens in a new tab) , CAPEC-183 (opens in a new tab) , CAPEC-248 (opens in a new tab) , CAPEC-40 (opens in a new tab) , CAPEC-43 (opens in a new tab) , CAPEC-75 (opens in a new tab) , CAPEC-76 (opens in a new tab)