On this page
Atomicorp WAF Rule 340193
Rule Summary
- Rule ID: 340193
- Status: Active
- Alert message: Atomicorp.com WAF Rules: CMD injection in URI
- Observed CWEs: CWE-20 (7), CWE-22 (2), CWE-73 (1), CWE-74 (7), CWE-77 (13), CWE-78 (70), CWE-88 (1), CWE-89 (5), CWE-93 (1), CWE-94 (26), CWE-95 (4), CWE-120 (1), CWE-121 (2), CWE-184 (1), CWE-200 (1), CWE-284 (1), CWE-285 (1), CWE-287 (1), CWE-288 (1), CWE-306 (2), CWE-352 (1), CWE-434 (7), CWE-470 (2), CWE-502 (6), CWE-639 (1), CWE-641 (1), CWE-787 (1), CWE-835 (1), CWE-862 (1), CWE-863 (3), CWE-918 (1), CWE-1336 (1), CWE-1392 (1)
- Revision: 17
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Request surfaces: Request URI
- Rule action: deny
- HTTP status: 403
- Public tags: Command Injection
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “CMD injection in URI” in the request URI. It evaluates during the request body phase and denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2025-34030 | sar2html <=3.2.2 Plot Parameter - Remote Code Execution | sar2html | 10.0 (v4.0) | Critical |
| CVE-2025-34037 | Linksys Routers E/WAG/WAP/WES/WET/WRT-Series | E4200 | 10.0 (v4.0) | Critical |
| CVE-2026-49869 | Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in AuthenticationFilter | kestra | 10.0 (v3.1) | Critical |
| CVE-2026-34838 | Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in AbstractSettingsCollection | group-office | 9.9 (v3.1) | Critical |
| CVE-2026-42454 | Termix: OS Command Injection in Docker Container Management Endpoints | Termix | 9.9 (v3.1) | Critical |
| CVE-2026-45629 | Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket Endpoint | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-55565 | Yamcs: Authenticated remote code execution via unescaped StreamSQL LIKE pattern compiled by Janino (LikeExpression) | yamcs | 9.9 (v3.1) | Critical |
| CVE-2026-72738 | Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameter | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72869 | Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72876 | Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.* | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-73294 | Semaphore U: OS Command Injection | semaphore | 9.9 (v3.1) | Critical |
| CVE-2014-3206 | Seagate BlackArmor NAS - Command Injection | blackarmor nas 220 firmware | 9.8 (v3.0) | Critical |
| CVE-2017-12611 | Apache Struts2 S2-053 - Remote Code Execution | struts | 9.8 (v3.0) | Critical |
| CVE-2020-28188 | TerraMaster TOS - Unauthenticated Remote Command Execution | tos | 9.8 (v3.1) | Critical |
| CVE-2020-35476 | OpenTSDB <=2.4.0 - Remote Code Execution | opentsdb | 9.8 (v3.1) | Critical |
| CVE-2021-20038 | SonicWall SMA100 Stack - Buffer Overflow/Remote Code Execution | sma 200 firmware | 9.8 (v3.1) | Critical |
| CVE-2021-32305 | Websvn <2.6.1 - Remote Code Execution | websvn | 9.8 (v3.1) | Critical |
| CVE-2022-2486 | Wavlink WN535K2/WN535K3 - OS Command Injection | wl-wn535k2 | 9.8 (v3.1) | Critical |
| CVE-2022-2488 | Wavlink WN535K2/WN535K3 - OS Command Injection | wl-wn535k2 firmware | 9.8 (v3.1) | Critical |
| CVE-2022-29078 | Node.js Embedded JavaScript 3.1.6 - Template Injection | ejs | 9.8 (v3.1) | Critical |
| CVE-2023-29827 | Embedded JavaScript(EJS) 3.1.6 - Template Injection | ejs | 9.8 (v3.1) | Critical |
| CVE-2023-46359 | cPH2 Charging Station v1.87.0 - OS Command Injection | cph2 echarge | 9.8 (v3.1) | Critical |
| CVE-2026-12940 | Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoint | langflow | 9.8 (v3.1) | Critical |
| CVE-2026-19912 | Kaltura HTML5 Video Player, html5 library Arbitrary Code Execution Vulnerability | Kaltura HTML5 Video Player, html5 library | 9.8 (v3.1) | Critical |
| CVE-2026-3296 | Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder | 9.8 (v3.1) | Critical |
| CVE-2026-35847 | dnsmgr 2.15 and Earlier Arbitrary Code Execution Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-37281 | the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 Command Injection Vulnerability | the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 | 9.8 (v3.1) | Critical |
| CVE-2026-38428 | kestra SQL Injection Vulnerability | kestra | 9.8 (v3.1) | Critical |
| CVE-2026-46562 | Yamcs: Remote Code Execution via Mission Database algorithm override | yamcs | 9.8 (v3.1) | Critical |
| CVE-2026-53545 | Termix: Remote Code Execution via Tunnel Disconnect pkill Command Injection | Termix | 9.8 (v3.1) | Critical |
| CVE-2026-84372 | Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections | predis | 9.8 (v3.1) | Critical |
| CVE-2026-35906 | An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 OS Command Injection Vulnerability | - | 9.6 (v3.1) | Critical |
| CVE-2026-8986 | Command Injection via Malicious OCPP Server | maxicharger single charger firmware | 9.5 (v4.0) | Critical |
| CVE-2026-39932 | OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection | openemr | 9.4 (v4.0) | Critical |
| CVE-2026-69256 | Flowise: Remote Code Execution Vulnerability in CSVAgent | Flowise | 9.4 (v4.0) | Critical |
| CVE-2018-25357 | Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php | dolibarr erp/crm | 9.3 (v4.0) | Critical |
| CVE-2024-9166 | TitanNit Web Control 2.01/Atemio 7600 - Remote Code Execution | Atemio AM 520 HD Full HD Satellite Receiver | 9.3 (v4.0) | Critical |
| CVE-2026-41939 | Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly | Care Everywhere Gateway | 9.3 (v4.0) | Critical |
| CVE-2026-44402 | Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi | SNMP Web Pro | 9.3 (v4.0) | Critical |
| CVE-2026-53975 | OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec | OpenChamber | 9.3 (v4.0) | Critical |
| CVE-2026-61498 | Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.php | flamingo | 9.3 (v4.0) | Critical |
| CVE-2026-61511 | vBulletin 6.x - Remote Code Execution | vBulletin | 9.3 (v4.0) | Critical |
| CVE-2026-63766 | GPT-SoVITS 20250606v2pro OS Command Injection via webui.py | GPT-SoVITS | 9.3 (v4.0) | Critical |
| CVE-2026-71921 | DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi | VigorSwitch G2540xs | 9.3 (v4.0) | Critical |
| CVE-2026-71946 | D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRun | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71947 | D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71948 | D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71955 | D-Link DWR-M961 Command Injection via /boafrm/formWsc | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71984 | MSI Radix AXE6600 v781521 Command Injection via urlfilter | Radix AXE6600 | 9.3 (v4.0) | Critical |
| CVE-2026-71992 | MSI Radix AXE6600 v781521 Command Injection via macfilter | Radix AXE6600 | 9.3 (v4.0) | Critical |
| CVE-2026-10042 | manga-image-translator RCE via Unsafe Pickle Deserialization in Share Model | manga-image-translator | 9.2 (v4.0) | Critical |
| CVE-2026-87930 | MaxSite CMS through 109.6 PHP Object Injection via ci_session | MaxSite CMS | 9.2 (v4.0) | Critical |
| CVE-2026-46621 | Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection | yamcs | 9.1 (v3.1) | Critical |
| CVE-2026-55511 | Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs executeSql | yamcs | 9.1 (v3.1) | Critical |
| CVE-2026-58400 | GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter | core-geonetwork | 9.1 (v3.1) | Critical |
| CVE-2026-14602 | Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter | Remote API | 9.0 (v3.1) | Critical |
| CVE-2026-34612 | Kestra: Remote Code Execution via SQL Injection | kestra | 9.0 (v3.1) | Critical |
| CVE-2026-62674 | Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE | omnigent | 9.0 (v3.1) | Critical |
| CVE-2026-69251 | Flowise RCE via TypeORM DataSource | Flowise | 9.0 (v4.0) | Critical |
| CVE-2026-43945 | FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection | FUXA | 8.9 (v4.0) | High |
| CVE-2026-73570 | zimbra collaboration suite Arbitrary Code Execution Vulnerability | zimbra collaboration suite | 8.9 (v3.1) | High |
| CVE-2017-6884 | Zyxel_ EMG2926 < V1.00(AAQT.4)b8 - OS Command Injection | emg2926 firmware | 8.8 (v3.1) | High |
| CVE-2020-15874 | Command Injection | - | 8.8 (v3.1) | High |
| CVE-2021-22053 | Spring Cloud Netflix Hystrix Dashboard <2.2.10 - Remote Code Execution | spring cloud netflix | 8.8 (v3.1) | High |
| CVE-2021-32819 | Nodejs Squirrelly - Remote Code Execution | squirrelly | 8.8 (v3.1) | High |
| CVE-2021-3577 | Motorola Baby Monitors - Remote Command Execution | halo+ camera firmware | 8.8 (v3.1) | High |
| CVE-2026-34197 | Apache ActiveMQ - Remote Code Execution | activemq | 8.8 (v3.1) | High |
| CVE-2026-35196 | Chamilo LMS has OS Command Injection via export_all_certificates action | chamilo lms | 8.8 (v3.1) | High |
| CVE-2026-72875 | Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFile | dokploy | 8.8 (v3.1) | High |
| CVE-2021-47943 | TextPattern CMS 4.8.7 Remote Code Execution via File Upload | TextPattern CMS | 8.7 (v4.0) | High |
| CVE-2022-50944 | Aero CMS 0.0.1 PHP Code Injection via posts.php | Aero CMS | 8.7 (v4.0) | High |
| CVE-2025-34115 | OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.php | OP5 Monitor | 8.7 (v4.0) | High |
| CVE-2025-71260 | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE | footprints | 8.7 (v4.0) | High |
| CVE-2026-34228 | Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write | emlog | 8.7 (v4.0) | High |
| CVE-2026-34735 | Hytale Modding Vulnerable to Remote Code Execution via File Upload Bypass in FileController | wiki | 8.7 (v4.0) | High |
| CVE-2026-34792 | Endian Firewall /cgi-bin/logs_clamav.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34793 | Endian Firewall /cgi-bin/logs_firewall.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34794 | Endian Firewall /cgi-bin/logs_ids.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34795 | Endian Firewall /cgi-bin/logs_log.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34796 | Endian Firewall /cgi-bin/logs_openvpn.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34797 | Endian Firewall /cgi-bin/logs_smtp.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-67206 | Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload | wolfcms | 8.7 (v4.0) | High |
| CVE-2026-71981 | Cypht < 2.12.2 PHP Object Injection RCE via back_query Parameter | cypht | 8.7 (v4.0) | High |
| CVE-2026-76060 | OS Command Injection in PayRange API | Zoneminder | 8.7 (v4.0) | High |
| CVE-2026-76836 | AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group Bypass | AzuraCast | 8.7 (v4.0) | High |
| CVE-2026-79756 | Nuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platform | nuclio | 8.7 (v4.0) | High |
| CVE-2026-85610 | OpenPanel before 2.3.0 Remote Code Execution via chart formulas | openpanel | 8.7 (v4.0) | High |
| CVE-2024-20353 | adaptive security appliance software Denial of Service Vulnerability | adaptive security appliance software | 8.6 (v3.1) | High |
| CVE-2026-40187 | Authenticated RCE via Malicious eTemplate Upload in EGroupware | egroupware | 8.6 (v4.0) | High |
| CVE-2026-42785 | OpenKM 6.3.12 Remote Code Execution via Administrative Scripting | OpenKM Community Edition | 8.6 (v4.0) | High |
| CVE-2026-53804 | OTRS Community Edition OS Command Injection via PGP Configuration | OTRS Community Edition | 8.6 (v4.0) | High |
| CVE-2026-56703 | Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTO | adminer | 8.6 (v4.0) | High |
| CVE-2026-67599 | ClearOS 7.9 OS Command Injection via Log Viewer filter parameter | ClearOS | 8.6 (v4.0) | High |
| CVE-2026-67608 | Telenia TVox 26.5.3 OS Command Injection via action_audio.php | TVox | 8.6 (v4.0) | High |
| CVE-2026-71908 | DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_test | VigorAP 918R | 8.6 (v4.0) | High |
| CVE-2026-71913 | DrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgi | VigorAP 918R | 8.6 (v4.0) | High |
| CVE-2026-71918 | DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupAction | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71919 | DrayTek VigorSwitch Multiple Models OS Command Injection via sysreboot | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71931 | DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgrade | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-75123 | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_post | PLANET GS-4210-16P2S V3 | 8.6 (v4.0) | High |
| CVE-2026-80214 | LibreNMS Virtualisation Discovery Module RCE | librenms | 8.6 (v4.0) | High |
| CVE-2026-82692 | D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection | DNS-340L | 8.6 (v4.0) | High |
| CVE-2026-86733 | Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore | snipe-it | 8.6 (v4.0) | High |
| CVE-2026-22244 | OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCE | openmetadata | 8.5 (v4.0) | High |
| CVE-2026-82690 | D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection | DNS-327L | 8.5 (v4.0) | High |
| CVE-2026-85222 | D-Link DNS-340L Add-On Center addon_center.cgi os command injection | DNS-340L | 8.5 (v4.0) | High |
| CVE-2026-85224 | D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection | DNS-320 ShareCenter | 8.5 (v4.0) | High |
| CVE-2018-11776 | Apache Struts2 S2-057 - Remote Code Execution | struts | 8.1 (v3.1) | High |
| CVE-2026-66738 | SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLite | SPIP | 7.7 (v4.0) | High |
| CVE-2026-19913 | Kaltura HTML5 Video Player, html5lib library Improper Input Validation Vulnerability | Kaltura HTML5 Video Player, html5lib library | 7.5 (v3.1) | High |
| CVE-2026-34239 | Chamilo Authenticated Remote Code Execution | chamilo-lms | 7.5 (v4.0) | High |
| CVE-2026-36783 | Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to Denial of Service Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2026-36796 | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to Denial of Service Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2026-46581 | mojarra Path Traversal Vulnerability | mojarra | 7.5 (v3.1) | High |
| CVE-2026-53599 | Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mo | core | 7.5 (v3.1) | High |
| CVE-2026-19771 | Baicells EG3661M LuCI Web luci os command injection | EG3661M | 7.3 (v4.0) | High |
| CVE-2021-33544 | Geutebruck - Remote Command Injection | g-cam ebc-2110 | 7.2 (v3.1) | High |
| CVE-2026-27891 | Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism | facturascripts | 7.2 (v3.1) | High |
| CVE-2025-71257 | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass | footprints itsm | 6.9 (v4.0) | Medium |
| CVE-2026-19983 | GL.iNet XE3000 NAS Command Service gl_nas_sys os command injection | A1300 | 6.9 (v4.0) | Medium |
| CVE-2026-45626 | Arcane: OS Command Injection in Volume Browser ListDirectory via path query parameter | arcane | 6.3 (v3.1) | Medium |
| CVE-2025-13786 | taosir WTCMS index.php fetch code injection | wtcms | 5.5 (v4.0) | Medium |
| CVE-2025-13792 | Qualitor getResumo.php eval code injection | Qualitor | 5.5 (v4.0) | Medium |
| CVE-2026-19379 | EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection | ipTIME AX8004M | 5.5 (v4.0) | Medium |
| CVE-2026-54611 | InstantCMS has Remote Code Execution in package installer | icms2 | 5.5 (v3.1) | Medium |
| CVE-2026-82598 | SeaCMS Template search.php parseIf code injection | SeaCMS | 5.5 (v4.0) | Medium |
| CVE-2026-9474 | yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injection | StudentManagementSystem | 5.5 (v4.0) | Medium |
| CVE-2023-7299 | DataGear resolveSql sql injection | datagear | 5.3 (v4.0) | Medium |
| CVE-2026-19785 | francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injection | RosarioSIS | 5.3 (v4.0) | Medium |
| CVE-2026-11408 | vertex-app vertex Log Viewer Endpoint LogMod.js os command injection | vertex | 2.1 (v4.0) | Low |
| CVE-2026-8191 | Wavlink NU516U1 adm.cgi wifi_region os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-82678 | diem-project diem Administrative Console actions.class.php executeCommand os command injection | diem | 2.0 (v4.0) | Low |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.