Atomicorp WAF Research Notes

Research Update - 2026-07-04

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2022-24816GeoServer <1.2.2 - Remote Code Execution337209 , 337210 , 337211 , 340121 , 344360 , 344370 , 380026
CVE-2024-4040CrushFTP VFS - Sandbox Escape LFR392301
CVE-2021-21345XStream < 1.4.16 - Remote Code Execution344363 , 344366
CVE-2024-9463PaloAlto Networks Expedition - Remote Code Execution344363
CVE-2013-7285XStream <1.4.6/1.4.10 - Remote Code Execution344363
CVE-2016-10108Western Digital MyCloud NAS - Command Injection344364 , 344366
CVE-2016-5674NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities344363 , 392301
CVE-2017-11165DataTaker DT80 dEX 1.50.012 - Information Disclosure390716
CVE-2017-14135OpenDreambox 2.0.0 - Remote Code Execution344364
CVE-2017-14942Intelbras WRN 150 - Authentication Bypass390716
CVE-2017-17731DedeCMS 5.7 - SQL Injection344370
CVE-2018-1000861Jenkins - Remote Command Injection344370 , 390722
CVE-2018-17153Western Digital MyCloud NAS - Authentication Bypass344363
CVE-2018-17431Comodo Unified Threat Management Web Console - Remote Code Execution344361 , 344362 , 344364 , 390722
CVE-2018-19276OpenMRS Platform < 2.24.0 - Insecure Object Deserialization330791 , 340152 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2018-7251Anchor CMS 0.12.3 - Error Log Exposure390716
CVE-2018-7282TITool PrintMonitor - Blind SQL Injection344370
CVE-2019-13372D-Link Central WiFi Manager CWM(100) - Remote Code Execution344370
CVE-2019-19781Citrix ADC and Gateway - Directory Traversal390716
CVE-2019-2729Oracle WebLogic Server Administration Console - Remote Code Execution344361 , 344370 , 393655
CVE-2019-5434Revive Adserver 4.2 - Remote Code Execution344362 , 344365 , 344370
CVE-2021-33357RaspAP <=2.6.5 - Remote Command Injection344363 , 344364 , 344366 , 344370
CVE-2021-42237Sitecore Experience Platform Pre-Auth RCE344362 , 344366
CVE-2022-25082TOTOLink - Unauthenticated Command Injection344361 , 344363
CVE-2022-31499Nortek Linear eMerge E3-Series <0.32-08f - Remote Command Injection344364 , 344366
CVE-2022-3236Sophos Firewall <= 19.0 MR1 - Remote Code Execution344361 , 344364
CVE-2022-34045WAVLINK WN530HG4 - Improper Access Control390716
CVE-2023-26802DCBI-Netlog-LAB v1.0 - Command Injection344361 , 344363
CVE-2023-28343Altenergy Power Control Software C1.2.5 - Remote Command Injection344364
CVE-2023-30258MagnusBilling - Remote Code Execution344363 , 344364 , 344366
CVE-2023-3368Chamilo LMS <= v1.11.20 Unauthenticated Command Injection344363 , 344370 , 393655
CVE-2023-34960Chamilo Command Injection341245 , 344360 , 344361 , 344363 , 344370
CVE-2023-34993Fortinet FortiWLM Unauthenticated Command Injection Vulnerability344363
CVE-2023-3710Honeywell PM43 Printers - Command Injection344361 , 344363
CVE-2023-37679NextGen Mirth Connect - Remote Code Execution344363
CVE-2023-41892CraftCMS < 4.4.15 - Unauthenticated Remote Code Execution344365
CVE-2023-43208NextGen Healthcare Mirth Connect - Remote Code Execution344363 , 344364 , 344380
CVE-2023-50917MajorDoMo thumb.php - OS Command Injection344363
CVE-2024-23692Rejetto HTTP File Server - Template injection344364 , 344366 , 390703 , 390722
CVE-2024-2389Progress Kemp Flowmon - Command Injection344363
CVE-2024-39914FOG Project < 1.5.10.34 - Remote Command Execution344363
CVE-2025-24799GLPI < 10.0.17 - Pre-Auth SQL Injection340156 , 341245 , 380026 , 380122
CVE-2025-44148MailEnable Mail Service < v10 - Cross-Site Scripting344363 , 346755
CVE-2025-45985Blink Router - Command Injection344363
CVE-2026-39808Fortinet FortiSandbox - Command Injection344363
CVE-2024-7332TOTOLINK CP450 v4.1.0cu.747_B20191224 - Hard-Coded Password Vulnerability390716
CVE-2025-25034SugarCRM - Unauthenticated Remote Code Execution via PHP Object Injection344370
CVE-2024-10914D-Link NAS - Command Injection via Name Parameter344363
CVE-2024-10915D-Link NAS - Command Injection via Group Parameter344363
CVE-2025-5086Dassault Systèmes DELMIA Apriso (up to 2025) - Insecure Deserialization331702 , 344380
CVE-2017-11610XML-RPC Server - Remote Code Execution344364
CVE-2017-9822DotNetNuke 5.0.0 - 9.3.0 - Cookie Deserialization Remote Code Execution344365 , 344370
CVE-2018-7700DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code Execution344370
CVE-2019-15642Webmin < 1.920 - Authenticated Remote Code Execution344362 , 344366
CVE-2019-20224Pandora FMS 7.0NG - Remote Command Injection344363
CVE-2020-26217XStream <1.4.14 - Remote Code Execution344363 , 344366
CVE-2022-33891Apache Spark UI - Remote Command Injection344361 , 344363
CVE-2022-3800IBAX - SQL Injection344366
CVE-2023-39108rConfig 3.9.4 - Server-Side Request Forgery340162 , 340165 , 344360 , 347009
CVE-2023-39109rConfig 3.9.4 - Server-Side Request Forgery340162 , 340165 , 344360 , 347009
CVE-2023-39110rConfig 3.9.4 - Server-Side Request Forgery340165 , 344360 , 347009
CVE-2024-29824Ivanti EPM - Remote Code Execution340155 , 341155 , 341245
CVE-2024-52875Kerio Control v9.2.5 - CRLF Injection390716
CVE-2023-7327Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File Read390716
CVE-2024-7029AVTECH IP Camera - Command Injection344363
CVE-2023-43662ShokoServer System - Local File Inclusion (LFI)344365 , 390716
CVE-2021-39144XStream 1.4.18 - Remote Code Execution344363
CVE-2017-15715Apache httpd <=2.4.29 - Arbitrary File Upload344365
CVE-2017-9805Apache Struts2 S2-052 - Remote Code Execution344360 , 344364 , 344366
CVE-2018-1000130Jolokia Agent - JNDI Code Injection344362 , 390724
CVE-2018-12455Intelbras NPLUG 1.0.0.14 - Authentication Bypass390716
CVE-2025-48828vBulletin replaceAdTemplate - Remote Code Execution344370
CVE-2017-10271Oracle WebLogic Server - Remote Command Execution344362 , 344363 , 344364 , 344366
CVE-2018-10201Ncomputing vSPace Pro 10 and 11 - Directory Traversal344365 , 390716
CVE-2018-15811DotNetNuke 9.2 - 9.2.1 - Weak Encryption & Cookie Deserialization344365 , 344370
CVE-2018-18325DotNetNuke 9.2 - 9.2.2 - Weak Encryption & Cookie Deserialization344365 , 344370
CVE-2018-8727Mirasys DVMS Workstation <=5.12.6 - Local File Inclusion390716
CVE-2019-14322Pallets Werkzeug <0.15.5 - Local File Inclusion390716
CVE-2019-19822TOTOLINK/Realtek Routers - Information Disclosure390716
CVE-2019-19823TOTOLINK/Realtek Routers - Information Disclosure390716
CVE-2020-10973WAVLINK - Access Control390716
CVE-2021-40150Reolink E1 Zoom Camera <=3.0.0.716 - Information Disclosure390716
CVE-2022-23854AVEVA InTouch Access Anywhere Secure Gateway - Local File Inclusion390716
CVE-2023-2766Weaver OA 9.5 - Information Disclosure390716
CVE-2023-32235Ghost CMS < 5.42.1 - Path Traversal390703
CVE-2023-40600EWWW Image Optimizer <= 7.2.0 - Unauthenticated Information Disclosure390716
CVE-2023-43261Milesight Routers - Information Disclosure390716
CVE-2023-44982WordPress Perfect Images (WP Retina 2x) < 6.4.6 - Sensitive Information Exposure390716
CVE-2023-48241XWiki < 4.10.15 - Information Disclosure390722
CVE-2024-12008W3 Total Cache < 2.8.2 - Log File Exposure390716
CVE-2024-20440Cisco Smart Licensing Utility UnAuthenticated Logs Exposure Leaking Plaintext Credentials390716
CVE-2025-12055MPDV Mikrolab GmbH HYDRA X, MIP 2 & FEDRA 2 - Path Traversal344365
CVE-2025-14437WordPress Hummingbird <= 3.18.0 - Sensitive Information Exposure via Log File390716
CVE-2024-11740Download Manager < 3.3.04 - Unauthenticated Arbitrary Shortcode Execution344370
CVE-2023-0669Fortra GoAnywhere MFT - Remote Code Execution344370
CVE-2022-35507Proxmox - CRLF Injection390714
CVE-2017-1000163Phoenix Framework - Open Redirect344365
CVE-2019-10092Apache HTTP Server <=2.4.39 - HTML Injection/Partial Cross-Site Scripting344365
CVE-2020-13483Bitrix24 <=20.0.0 - Cross-Site Scripting344363 , 344370 , 346755 , 390722
CVE-2021-25161Aruba Instant Access Point (IAP) - Cross-Site Scripting344370 , 346755 , 390722
CVE-2022-48012OpenCATS 0.9.7 - Cross-Site Scripting340147 , 340148 , 341256 , 342259 , 346755
CVE-2023-2256WordPress Product Addons & Fields for WooCommerce < 32.0.7 - Cross-Site Scripting341266 , 346755
CVE-2023-2948OpenEMR < 7.0.1 - Cross-Site Scripting344363 , 346755
CVE-2018-1271Spring MVC Framework - Local File Inclusion390716
CVE-2021-40149Reolink E1 Zoom Camera <=3.0.0.716 - Private Key Disclosure390716
CVE-2017-9965Schneider Electric Pelco VideoXpert Enterprise 2.0 - Path Traversal344365 , 390716
CVE-2025-14528D-Link DIR-803 - Authentication Bypass390722
CVE-2017-12544HPE System Management - Cross-Site Scripting344366
CVE-2017-3528Oracle E-Business Suite 12.1.3/12.2.x - Open Redirect344365
CVE-2020-12256rConfig 3.9.4 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2020-12259rConfig 3.9.4 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-25356Alt-n/MDaemon Security Gateway <=8.5.0 - XML Injection390716
CVE-2024-33113D-LINK DIR-845L bsc_sms_inbox.php file - Information Disclosure390722
CVE-2024-7120Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 - Command Injection344363 , 344370
CVE-2025-322571 Click WordPress Migration <= 2.2 - Unauthenticated Information Disclsoure390716
CVE-2025-9985Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File390716
CVE-2022-40843Tenda AC1200 V-W15Ev2 - Authentication Bypass390716
CVE-2008-1547Microsoft OWA Exchange Server 2003 - 'redir.asp' Open Redirection390716
CVE-2011-4640WebTitan < 3.60 - Local File Inclusion340007 , 344360 , 347009 , 390709