Atomicorp WAF Research Notes
Research Update - 2026-07-04
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2022-24816 | GeoServer <1.2.2 - Remote Code Execution | 337209 , 337210 , 337211 , 340121 , 344360 , 344370 , 380026 |
| CVE-2024-4040 | CrushFTP VFS - Sandbox Escape LFR | 392301 |
| CVE-2021-21345 | XStream < 1.4.16 - Remote Code Execution | 344363 , 344366 |
| CVE-2024-9463 | PaloAlto Networks Expedition - Remote Code Execution | 344363 |
| CVE-2013-7285 | XStream <1.4.6/1.4.10 - Remote Code Execution | 344363 |
| CVE-2016-10108 | Western Digital MyCloud NAS - Command Injection | 344364 , 344366 |
| CVE-2016-5674 | NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities | 344363 , 392301 |
| CVE-2017-11165 | DataTaker DT80 dEX 1.50.012 - Information Disclosure | 390716 |
| CVE-2017-14135 | OpenDreambox 2.0.0 - Remote Code Execution | 344364 |
| CVE-2017-14942 | Intelbras WRN 150 - Authentication Bypass | 390716 |
| CVE-2017-17731 | DedeCMS 5.7 - SQL Injection | 344370 |
| CVE-2018-1000861 | Jenkins - Remote Command Injection | 344370 , 390722 |
| CVE-2018-17153 | Western Digital MyCloud NAS - Authentication Bypass | 344363 |
| CVE-2018-17431 | Comodo Unified Threat Management Web Console - Remote Code Execution | 344361 , 344362 , 344364 , 390722 |
| CVE-2018-19276 | OpenMRS Platform < 2.24.0 - Insecure Object Deserialization | 330791 , 340152 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2018-7251 | Anchor CMS 0.12.3 - Error Log Exposure | 390716 |
| CVE-2018-7282 | TITool PrintMonitor - Blind SQL Injection | 344370 |
| CVE-2019-13372 | D-Link Central WiFi Manager CWM(100) - Remote Code Execution | 344370 |
| CVE-2019-19781 | Citrix ADC and Gateway - Directory Traversal | 390716 |
| CVE-2019-2729 | Oracle WebLogic Server Administration Console - Remote Code Execution | 344361 , 344370 , 393655 |
| CVE-2019-5434 | Revive Adserver 4.2 - Remote Code Execution | 344362 , 344365 , 344370 |
| CVE-2021-33357 | RaspAP <=2.6.5 - Remote Command Injection | 344363 , 344364 , 344366 , 344370 |
| CVE-2021-42237 | Sitecore Experience Platform Pre-Auth RCE | 344362 , 344366 |
| CVE-2022-25082 | TOTOLink - Unauthenticated Command Injection | 344361 , 344363 |
| CVE-2022-31499 | Nortek Linear eMerge E3-Series <0.32-08f - Remote Command Injection | 344364 , 344366 |
| CVE-2022-3236 | Sophos Firewall <= 19.0 MR1 - Remote Code Execution | 344361 , 344364 |
| CVE-2022-34045 | WAVLINK WN530HG4 - Improper Access Control | 390716 |
| CVE-2023-26802 | DCBI-Netlog-LAB v1.0 - Command Injection | 344361 , 344363 |
| CVE-2023-28343 | Altenergy Power Control Software C1.2.5 - Remote Command Injection | 344364 |
| CVE-2023-30258 | MagnusBilling - Remote Code Execution | 344363 , 344364 , 344366 |
| CVE-2023-3368 | Chamilo LMS <= v1.11.20 Unauthenticated Command Injection | 344363 , 344370 , 393655 |
| CVE-2023-34960 | Chamilo Command Injection | 341245 , 344360 , 344361 , 344363 , 344370 |
| CVE-2023-34993 | Fortinet FortiWLM Unauthenticated Command Injection Vulnerability | 344363 |
| CVE-2023-3710 | Honeywell PM43 Printers - Command Injection | 344361 , 344363 |
| CVE-2023-37679 | NextGen Mirth Connect - Remote Code Execution | 344363 |
| CVE-2023-41892 | CraftCMS < 4.4.15 - Unauthenticated Remote Code Execution | 344365 |
| CVE-2023-43208 | NextGen Healthcare Mirth Connect - Remote Code Execution | 344363 , 344364 , 344380 |
| CVE-2023-50917 | MajorDoMo thumb.php - OS Command Injection | 344363 |
| CVE-2024-23692 | Rejetto HTTP File Server - Template injection | 344364 , 344366 , 390703 , 390722 |
| CVE-2024-2389 | Progress Kemp Flowmon - Command Injection | 344363 |
| CVE-2024-39914 | FOG Project < 1.5.10.34 - Remote Command Execution | 344363 |
| CVE-2025-24799 | GLPI < 10.0.17 - Pre-Auth SQL Injection | 340156 , 341245 , 380026 , 380122 |
| CVE-2025-44148 | MailEnable Mail Service < v10 - Cross-Site Scripting | 344363 , 346755 |
| CVE-2025-45985 | Blink Router - Command Injection | 344363 |
| CVE-2026-39808 | Fortinet FortiSandbox - Command Injection | 344363 |
| CVE-2024-7332 | TOTOLINK CP450 v4.1.0cu.747_B20191224 - Hard-Coded Password Vulnerability | 390716 |
| CVE-2025-25034 | SugarCRM - Unauthenticated Remote Code Execution via PHP Object Injection | 344370 |
| CVE-2024-10914 | D-Link NAS - Command Injection via Name Parameter | 344363 |
| CVE-2024-10915 | D-Link NAS - Command Injection via Group Parameter | 344363 |
| CVE-2025-5086 | Dassault Systèmes DELMIA Apriso (up to 2025) - Insecure Deserialization | 331702 , 344380 |
| CVE-2017-11610 | XML-RPC Server - Remote Code Execution | 344364 |
| CVE-2017-9822 | DotNetNuke 5.0.0 - 9.3.0 - Cookie Deserialization Remote Code Execution | 344365 , 344370 |
| CVE-2018-7700 | DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code Execution | 344370 |
| CVE-2019-15642 | Webmin < 1.920 - Authenticated Remote Code Execution | 344362 , 344366 |
| CVE-2019-20224 | Pandora FMS 7.0NG - Remote Command Injection | 344363 |
| CVE-2020-26217 | XStream <1.4.14 - Remote Code Execution | 344363 , 344366 |
| CVE-2022-33891 | Apache Spark UI - Remote Command Injection | 344361 , 344363 |
| CVE-2022-3800 | IBAX - SQL Injection | 344366 |
| CVE-2023-39108 | rConfig 3.9.4 - Server-Side Request Forgery | 340162 , 340165 , 344360 , 347009 |
| CVE-2023-39109 | rConfig 3.9.4 - Server-Side Request Forgery | 340162 , 340165 , 344360 , 347009 |
| CVE-2023-39110 | rConfig 3.9.4 - Server-Side Request Forgery | 340165 , 344360 , 347009 |
| CVE-2024-29824 | Ivanti EPM - Remote Code Execution | 340155 , 341155 , 341245 |
| CVE-2024-52875 | Kerio Control v9.2.5 - CRLF Injection | 390716 |
| CVE-2023-7327 | Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File Read | 390716 |
| CVE-2024-7029 | AVTECH IP Camera - Command Injection | 344363 |
| CVE-2023-43662 | ShokoServer System - Local File Inclusion (LFI) | 344365 , 390716 |
| CVE-2021-39144 | XStream 1.4.18 - Remote Code Execution | 344363 |
| CVE-2017-15715 | Apache httpd <=2.4.29 - Arbitrary File Upload | 344365 |
| CVE-2017-9805 | Apache Struts2 S2-052 - Remote Code Execution | 344360 , 344364 , 344366 |
| CVE-2018-1000130 | Jolokia Agent - JNDI Code Injection | 344362 , 390724 |
| CVE-2018-12455 | Intelbras NPLUG 1.0.0.14 - Authentication Bypass | 390716 |
| CVE-2025-48828 | vBulletin replaceAdTemplate - Remote Code Execution | 344370 |
| CVE-2017-10271 | Oracle WebLogic Server - Remote Command Execution | 344362 , 344363 , 344364 , 344366 |
| CVE-2018-10201 | Ncomputing vSPace Pro 10 and 11 - Directory Traversal | 344365 , 390716 |
| CVE-2018-15811 | DotNetNuke 9.2 - 9.2.1 - Weak Encryption & Cookie Deserialization | 344365 , 344370 |
| CVE-2018-18325 | DotNetNuke 9.2 - 9.2.2 - Weak Encryption & Cookie Deserialization | 344365 , 344370 |
| CVE-2018-8727 | Mirasys DVMS Workstation <=5.12.6 - Local File Inclusion | 390716 |
| CVE-2019-14322 | Pallets Werkzeug <0.15.5 - Local File Inclusion | 390716 |
| CVE-2019-19822 | TOTOLINK/Realtek Routers - Information Disclosure | 390716 |
| CVE-2019-19823 | TOTOLINK/Realtek Routers - Information Disclosure | 390716 |
| CVE-2020-10973 | WAVLINK - Access Control | 390716 |
| CVE-2021-40150 | Reolink E1 Zoom Camera <=3.0.0.716 - Information Disclosure | 390716 |
| CVE-2022-23854 | AVEVA InTouch Access Anywhere Secure Gateway - Local File Inclusion | 390716 |
| CVE-2023-2766 | Weaver OA 9.5 - Information Disclosure | 390716 |
| CVE-2023-32235 | Ghost CMS < 5.42.1 - Path Traversal | 390703 |
| CVE-2023-40600 | EWWW Image Optimizer <= 7.2.0 - Unauthenticated Information Disclosure | 390716 |
| CVE-2023-43261 | Milesight Routers - Information Disclosure | 390716 |
| CVE-2023-44982 | WordPress Perfect Images (WP Retina 2x) < 6.4.6 - Sensitive Information Exposure | 390716 |
| CVE-2023-48241 | XWiki < 4.10.15 - Information Disclosure | 390722 |
| CVE-2024-12008 | W3 Total Cache < 2.8.2 - Log File Exposure | 390716 |
| CVE-2024-20440 | Cisco Smart Licensing Utility UnAuthenticated Logs Exposure Leaking Plaintext Credentials | 390716 |
| CVE-2025-12055 | MPDV Mikrolab GmbH HYDRA X, MIP 2 & FEDRA 2 - Path Traversal | 344365 |
| CVE-2025-14437 | WordPress Hummingbird <= 3.18.0 - Sensitive Information Exposure via Log File | 390716 |
| CVE-2024-11740 | Download Manager < 3.3.04 - Unauthenticated Arbitrary Shortcode Execution | 344370 |
| CVE-2023-0669 | Fortra GoAnywhere MFT - Remote Code Execution | 344370 |
| CVE-2022-35507 | Proxmox - CRLF Injection | 390714 |
| CVE-2017-1000163 | Phoenix Framework - Open Redirect | 344365 |
| CVE-2019-10092 | Apache HTTP Server <=2.4.39 - HTML Injection/Partial Cross-Site Scripting | 344365 |
| CVE-2020-13483 | Bitrix24 <=20.0.0 - Cross-Site Scripting | 344363 , 344370 , 346755 , 390722 |
| CVE-2021-25161 | Aruba Instant Access Point (IAP) - Cross-Site Scripting | 344370 , 346755 , 390722 |
| CVE-2022-48012 | OpenCATS 0.9.7 - Cross-Site Scripting | 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2023-2256 | WordPress Product Addons & Fields for WooCommerce < 32.0.7 - Cross-Site Scripting | 341266 , 346755 |
| CVE-2023-2948 | OpenEMR < 7.0.1 - Cross-Site Scripting | 344363 , 346755 |
| CVE-2018-1271 | Spring MVC Framework - Local File Inclusion | 390716 |
| CVE-2021-40149 | Reolink E1 Zoom Camera <=3.0.0.716 - Private Key Disclosure | 390716 |
| CVE-2017-9965 | Schneider Electric Pelco VideoXpert Enterprise 2.0 - Path Traversal | 344365 , 390716 |
| CVE-2025-14528 | D-Link DIR-803 - Authentication Bypass | 390722 |
| CVE-2017-12544 | HPE System Management - Cross-Site Scripting | 344366 |
| CVE-2017-3528 | Oracle E-Business Suite 12.1.3/12.2.x - Open Redirect | 344365 |
| CVE-2020-12256 | rConfig 3.9.4 - Cross-Site Scripting | 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2020-12259 | rConfig 3.9.4 - Cross-Site Scripting | 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2022-25356 | Alt-n/MDaemon Security Gateway <=8.5.0 - XML Injection | 390716 |
| CVE-2024-33113 | D-LINK DIR-845L bsc_sms_inbox.php file - Information Disclosure | 390722 |
| CVE-2024-7120 | Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 - Command Injection | 344363 , 344370 |
| CVE-2025-32257 | 1 Click WordPress Migration <= 2.2 - Unauthenticated Information Disclsoure | 390716 |
| CVE-2025-9985 | Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File | 390716 |
| CVE-2022-40843 | Tenda AC1200 V-W15Ev2 - Authentication Bypass | 390716 |
| CVE-2008-1547 | Microsoft OWA Exchange Server 2003 - 'redir.asp' Open Redirection | 390716 |
| CVE-2011-4640 | WebTitan < 3.60 - Local File Inclusion | 340007 , 344360 , 347009 , 390709 |