Atomicorp WAF Research Notes
Research Update - 2026-07-04
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
- CVE-2024-2389 - Progress Kemp Flowmon - Command Injection - rules observed: 344363
- CVE-2024-4040 - CrushFTP VFS - Sandbox Escape LFR - rules observed: 392301
- CVE-2025-48828 - vBulletin replaceAdTemplate - Remote Code Execution - rules observed: 344370
- CVE-2021-21345 - XStream < 1.4.16 - Remote Code Execution - rules observed: 344363
- CVE-2024-9463 - PaloAlto Networks Expedition - Remote Code Execution - rules observed: 344363
- CVE-2013-7285 - XStream <1.4.6/1.4.10 - Remote Code Execution - rules observed: 344363
- CVE-2016-10108 - Western Digital MyCloud NAS - Command Injection - rules observed: 344364
- CVE-2016-5674
- NUUO NVR camera
debugging_center_utils_.php- Command Execution - rules observed: 344363 - CVE-2017-11165 - DataTaker DT80 dEX 1.50.012 - Information Disclosure - rules observed: 390716
- CVE-2017-14135 - OpenDreambox 2.0.0 - Remote Code Execution - rules observed: 344364
- CVE-2017-14942 - Intelbras WRN 150 - Authentication Bypass - rules observed: 390716
- CVE-2017-17731 - DedeCMS 5.7 - SQL Injection - rules observed: 344370
- CVE-2018-1000861 - Jenkins - Remote Command Injection - rules observed: 390722
- CVE-2018-17153 - Western Digital MyCloud NAS - Authentication Bypass - rules observed: 344363
- CVE-2018-17431 - Comodo Unified Threat Management Web Console - Remote Code Execution - rules observed: 390722
- CVE-2018-19276 - OpenMRS Platform < 2.24.0 - Insecure Object Deserialization - rules observed: 344366
- CVE-2018-7251 - Anchor CMS 0.12.3 - Error Log Exposure - rules observed: 390716
- CVE-2018-7282 - TITool PrintMonitor - Blind SQL Injection - rules observed: 344370
- CVE-2018-7841 - Schneider Electric U.motion Builder - Remote Code Execution - rules observed: 344364
- CVE-2019-13372 - D-Link Central WiFi Manager CWM(100) - Remote Code Execution - rules observed: 344370
- CVE-2019-19781 - Citrix ADC and Gateway - Directory Traversal - rules observed: 390716
- CVE-2019-2729 - Oracle WebLogic Server Administration Console - Remote Code Execution - rules observed: 393655
- CVE-2019-5434 - Revive Adserver 4.2 - Remote Code Execution - rules observed: 344362
- CVE-2020-22209 - 74cms - ajax_common.php SQL Injection - rules observed: 390703
- CVE-2021-31856 - Layer5 Meshery 0.5.2 - SQL Injection - rules observed: 344366
- CVE-2021-33357 - RaspAP <=2.6.5 - Remote Command Injection - rules observed: 344363
- CVE-2021-42237 - Sitecore Experience Platform Pre-Auth RCE - rules observed: 344362
- CVE-2022-24816 - GeoServer <1.2.2 - Remote Code Execution - rules observed: 344360
- CVE-2022-25082 - TOTOLink - Unauthenticated Command Injection - rules observed: 344361
- CVE-2022-31499 - Nortek Linear eMerge E3-Series <0.32-08f - Remote Command Injection - rules observed: 344364
- CVE-2022-3236 - Sophos Firewall <= 19.0 MR1 - Remote Code Execution - rules observed: 344361
- CVE-2022-34045 - WAVLINK WN530HG4 - Improper Access Control - rules observed: 390716
- CVE-2023-26802 - DCBI-Netlog-LAB v1.0 - Command Injection - rules observed: 344361
- CVE-2023-28343 - Altenergy Power Control Software C1.2.5 - Remote Command Injection - rules observed: 344364
- CVE-2023-30258 - MagnusBilling - Remote Code Execution - rules observed: 344363, 344364
- CVE-2023-3368 - Chamilo LMS <= v1.11.20 Unauthenticated Command Injection - rules observed: 393655
- CVE-2023-34960 - Chamilo Command Injection - rules observed: 344360
- CVE-2023-34993 - Fortinet FortiWLM Unauthenticated Command Injection Vulnerability - rules observed: 344363
- CVE-2023-3710 - Honeywell PM43 Printers - Command Injection - rules observed: 344361
- CVE-2023-37679 - NextGen Mirth Connect - Remote Code Execution - rules observed: 344363
- CVE-2023-41892 - CraftCMS < 4.4.15 - Unauthenticated Remote Code Execution - rules observed: 344365
- CVE-2023-43208 - NextGen Healthcare Mirth Connect - Remote Code Execution - rules observed: 344363
- CVE-2023-50917 - MajorDoMo thumb.php - OS Command Injection - rules observed: 344363
- CVE-2024-10914 - D-Link NAS - Command Injection via Name Parameter - rules observed: 344363
- CVE-2024-10915 - D-Link NAS - Command Injection via Group Parameter - rules observed: 344363
- CVE-2024-23692 - Rejetto HTTP File Server - Template injection - rules observed: 390703
- CVE-2024-39914 - FOG Project < 1.5.10.34 - Remote Command Execution - rules observed: 344363
- CVE-2024-7332 - TOTOLINK CP450 v4.1.0cu.747_B20191224 - Hard-Coded Password Vulnerability - rules observed: 390716
- CVE-2025-45985 - Blink Router - Command Injection - rules observed: 344363
- CVE-2026-39808 - Fortinet FortiSandbox - Command Injection - rules observed: 344363
- CVE-2024-29824 - Ivanti EPM - Remote Code Execution - rules observed: 340155
- CVE-2025-25034 - SugarCRM - Unauthenticated Remote Code Execution via PHP Object Injection - rules observed: 344370
- CVE-2025-5086 - Dassault Systèmes DELMIA Apriso (up to 2025) - Insecure Deserialization - rules observed: 331702
- CVE-2017-11610 - XML-RPC Server - Remote Code Execution - rules observed: 344364
- CVE-2017-9822 - DotNetNuke 5.0.0 - 9.3.0 - Cookie Deserialization Remote Code Execution - rules observed: 344365
- CVE-2018-7700 - DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code Execution - rules observed: 344370
- CVE-2019-15642 - Webmin < 1.920 - Authenticated Remote Code Execution - rules observed: 344362
- CVE-2019-20224 - Pandora FMS 7.0NG - Remote Command Injection - rules observed: 344363
- CVE-2020-26217 - XStream <1.4.14 - Remote Code Execution - rules observed: 344363
- CVE-2022-33891 - Apache Spark UI - Remote Command Injection - rules observed: 344361
- CVE-2022-3800 - IBAX - SQL Injection - rules observed: 344366
- CVE-2023-39108 - rConfig 3.9.4 - Server-Side Request Forgery - rules observed: 347009
- CVE-2023-39109 - rConfig 3.9.4 - Server-Side Request Forgery - rules observed: 347009
- CVE-2023-39110 - rConfig 3.9.4 - Server-Side Request Forgery - rules observed: 347009
- CVE-2024-7029 - AVTECH IP Camera - Command Injection - rules observed: 344363
- CVE-2023-43662 - ShokoServer System - Local File Inclusion (LFI) - rules observed: 390716
- CVE-2021-39144 - XStream 1.4.18 - Remote Code Execution - rules observed: 344363
- CVE-2017-15715 - Apache httpd <=2.4.29 - Arbitrary File Upload - rules observed: 344365
- CVE-2017-9805 - Apache Struts2 S2-052 - Remote Code Execution - rules observed: 344360
- CVE-2018-1000130 - Jolokia Agent - JNDI Code Injection - rules observed: 344362
- CVE-2018-12455 - Intelbras NPLUG 1.0.0.14 - Authentication Bypass - rules observed: 390716
- CVE-2015-2080 - Eclipse Jetty <9.2.9.v20150224 - Sensitive Information Leakage - rules observed: 344365
- CVE-2017-10271 - Oracle WebLogic Server - Remote Command Execution - rules observed: 344362
- CVE-2018-10201 - Ncomputing vSPace Pro 10 and 11 - Directory Traversal - rules observed: 390716
- CVE-2018-15811 - DotNetNuke 9.2 - 9.2.1 - Weak Encryption & Cookie Deserialization - rules observed: 344365
- CVE-2018-18325 - DotNetNuke 9.2 - 9.2.2 - Weak Encryption & Cookie Deserialization - rules observed: 344365
- CVE-2018-8727 - Mirasys DVMS Workstation <=5.12.6 - Local File Inclusion - rules observed: 390716
- CVE-2019-14322 - Pallets Werkzeug <0.15.5 - Local File Inclusion - rules observed: 390716
- CVE-2019-19822 - TOTOLINK/Realtek Routers - Information Disclosure - rules observed: 390716
- CVE-2019-19823 - TOTOLINK/Realtek Routers - Information Disclosure - rules observed: 390716
- CVE-2020-10973 - WAVLINK - Access Control - rules observed: 390716
- CVE-2021-40150 - Reolink E1 Zoom Camera <=3.0.0.716 - Information Disclosure - rules observed: 390716
- CVE-2022-23854 - AVEVA InTouch Access Anywhere Secure Gateway - Local File Inclusion - rules observed: 390716
- CVE-2023-2766 - Weaver OA 9.5 - Information Disclosure - rules observed: 390716
- CVE-2023-32235 - Ghost CMS < 5.42.1 - Path Traversal - rules observed: 390703
- CVE-2023-43261 - Milesight Routers - Information Disclosure - rules observed: 390716
- CVE-2023-48241 - XWiki < 4.10.15 - Information Disclosure - rules observed: 390722
- CVE-2024-20440 - Cisco Smart Licensing Utility UnAuthenticated Logs Exposure Leaking Plaintext Credentials - rules observed: 390716
- CVE-2025-12055 - MPDV Mikrolab GmbH HYDRA X, MIP 2 & FEDRA 2 - Path Traversal - rules observed: 344365
- CVE-2025-14437 - WordPress Hummingbird <= 3.18.0 - Sensitive Information Exposure via Log File - rules observed: 390716
- CVE-2025-24799 - GLPI < 10.0.17 - Pre-Auth SQL Injection - rules observed: 380122
- CVE-2024-11740 - Download Manager < 3.3.04 - Unauthenticated Arbitrary Shortcode Execution - rules observed: 344370
- CVE-2025-10090 - Jinher OA - SQL Injection - rules observed: 344366
- CVE-2023-0669 - Fortra GoAnywhere MFT - Remote Code Execution - rules observed: 344370
- CVE-2022-35507 - Proxmox - CRLF Injection - rules observed: 390714
- CVE-2024-7120 - Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 - Command Injection - rules observed: 344363
- CVE-2017-1000163 - Phoenix Framework - Open Redirect - rules observed: 344365
- CVE-2019-10092 - Apache HTTP Server <=2.4.39 - HTML Injection/Partial Cross-Site Scripting - rules observed: 344365
- CVE-2020-13483 - Bitrix24 <=20.0.0 - Cross-Site Scripting - rules observed: 344363, 390722
- CVE-2021-25161 - Aruba Instant Access Point (IAP) - Cross-Site Scripting - rules observed: 390722
- CVE-2021-42551 - NetBiblio WebOPAC - Cross-Site Scripting - rules observed: 344370
- CVE-2022-48012 - OpenCATS 0.9.7 - Cross-Site Scripting - rules observed: 340147
- CVE-2023-2256 - WordPress Product Addons & Fields for WooCommerce < 32.0.7 - Cross-Site Scripting - rules observed: 341266
- CVE-2023-2948 - OpenEMR < 7.0.1 - Cross-Site Scripting - rules observed: 344363
- CVE-2018-1271 - Spring MVC Framework - Local File Inclusion - rules observed: 390716
- CVE-2021-40149 - Reolink E1 Zoom Camera <=3.0.0.716 - Private Key Disclosure - rules observed: 390716
- CVE-2017-9965 - Schneider Electric Pelco VideoXpert Enterprise 2.0 - Path Traversal - rules observed: 390716
- CVE-2017-12544 - HPE System Management - Cross-Site Scripting - rules observed: 344366
- CVE-2017-3528 - Oracle E-Business Suite 12.1.3/12.2.x - Open Redirect - rules observed: 344365
- CVE-2020-12256 - rConfig 3.9.4 - Cross-Site Scripting - rules observed: 341266
- CVE-2020-12259 - rConfig 3.9.4 - Cross-Site Scripting - rules observed: 341266
- CVE-2025-44148 - MailEnable Mail Service < v10 - Cross-Site Scripting - rules observed: 344363
- CVE-2022-25356 - Alt-n/MDaemon Security Gateway <=8.5.0 - XML Injection - rules observed: 390716
- CVE-2023-44982 - WordPress Perfect Images (WP Retina 2x) < 6.4.6 - Sensitive Information Exposure - rules observed: 390716
- CVE-2024-12008 - W3 Total Cache < 2.8.2 - Log File Exposure - rules observed: 390716
- CVE-2025-14528 - D-Link DIR-803 - Authentication Bypass - rules observed: 390722
- CVE-2022-40843 - Tenda AC1200 V-W15Ev2 - Authentication Bypass - rules observed: 390716
- CVE-2008-1547 - Microsoft OWA Exchange Server 2003 - ‘redir.asp’ Open Redirection - rules observed: 390716
- CVE-2011-4640 - WebTitan < 3.60 - Local File Inclusion - rules observed: 347009
- CVE-2023-40600 - EWWW Image Optimizer <= 7.2.0 - Unauthenticated Information Disclosure - rules observed: 390716
- CVE-2023-7327 - Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File Read - rules observed: 390716
- CVE-2024-33113 - D-LINK DIR-845L bsc_sms_inbox.php file - Information Disclosure - rules observed: 390722
- CVE-2024-52875 - Kerio Control v9.2.5 - CRLF Injection - rules observed: 390716
- CVE-2025-32257 - 1 Click WordPress Migration <= 2.2 - Unauthenticated Information Disclsoure - rules observed: 390716
- CVE-2025-9985 - Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File - rules observed: 390716
- CVE-2026-11111 - Research note for exploit techniques associated with CVE-2026-11111 - rules observed: 340016, 340162
- CVE-2026-48907 - Research note for exploit techniques associated with CVE-2026-48907 - rules observed: 383871, 333360