On this page

Atomicorp WAF Rule 340193

Rule Summary

Description

This rule detects behavior identified by its current alert as “CMD injection in URI” in the request URI. It evaluates during the request body phase and denies matching traffic with HTTP status 403.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2025-34030sar2html <=3.2.2 Plot Parameter - Remote Code Executionsar2html10.0 (v4.0)Critical
CVE-2025-34037Linksys Routers E/WAG/WAP/WES/WET/WRT-SeriesE420010.0 (v4.0)Critical
CVE-2026-49869Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in AuthenticationFilterkestra10.0 (v3.1)Critical
CVE-2026-34838Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in AbstractSettingsCollectiongroup-office9.9 (v3.1)Critical
CVE-2026-42454Termix: OS Command Injection in Docker Container Management EndpointsTermix9.9 (v3.1)Critical
CVE-2026-45629Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket Endpointdokploy9.9 (v3.1)Critical
CVE-2026-55565Yamcs: Authenticated remote code execution via unescaped StreamSQL LIKE pattern compiled by Janino (LikeExpression)yamcs9.9 (v3.1)Critical
CVE-2026-72738Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameterdokploy9.9 (v3.1)Critical
CVE-2026-72869Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCEdokploy9.9 (v3.1)Critical
CVE-2026-72876Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.*dokploy9.9 (v3.1)Critical
CVE-2026-73294Semaphore U: OS Command Injectionsemaphore9.9 (v3.1)Critical
CVE-2014-3206Seagate BlackArmor NAS - Command Injectionblackarmor nas 220 firmware9.8 (v3.0)Critical
CVE-2017-12611Apache Struts2 S2-053 - Remote Code Executionstruts9.8 (v3.0)Critical
CVE-2020-28188TerraMaster TOS - Unauthenticated Remote Command Executiontos9.8 (v3.1)Critical
CVE-2020-35476OpenTSDB <=2.4.0 - Remote Code Executionopentsdb9.8 (v3.1)Critical
CVE-2021-20038SonicWall SMA100 Stack - Buffer Overflow/Remote Code Executionsma 200 firmware9.8 (v3.1)Critical
CVE-2021-32305Websvn <2.6.1 - Remote Code Executionwebsvn9.8 (v3.1)Critical
CVE-2022-2486Wavlink WN535K2/WN535K3 - OS Command Injectionwl-wn535k29.8 (v3.1)Critical
CVE-2022-2488Wavlink WN535K2/WN535K3 - OS Command Injectionwl-wn535k2 firmware9.8 (v3.1)Critical
CVE-2022-29078Node.js Embedded JavaScript 3.1.6 - Template Injectionejs9.8 (v3.1)Critical
CVE-2023-29827Embedded JavaScript(EJS) 3.1.6 - Template Injectionejs9.8 (v3.1)Critical
CVE-2023-46359cPH2 Charging Station v1.87.0 - OS Command Injectioncph2 echarge9.8 (v3.1)Critical
CVE-2026-12940Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpointlangflow9.8 (v3.1)Critical
CVE-2026-19912Kaltura HTML5 Video Player, html5 library Arbitrary Code Execution VulnerabilityKaltura HTML5 Video Player, html5 library9.8 (v3.1)Critical
CVE-2026-3296Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry MetadataEverest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder9.8 (v3.1)Critical
CVE-2026-35847dnsmgr 2.15 and Earlier Arbitrary Code Execution Vulnerability-9.8 (v3.1)Critical
CVE-2026-37281the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 Command Injection Vulnerabilitythe /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.09.8 (v3.1)Critical
CVE-2026-38428kestra SQL Injection Vulnerabilitykestra9.8 (v3.1)Critical
CVE-2026-46562Yamcs: Remote Code Execution via Mission Database algorithm overrideyamcs9.8 (v3.1)Critical
CVE-2026-53545Termix: Remote Code Execution via Tunnel Disconnect pkill Command InjectionTermix9.8 (v3.1)Critical
CVE-2026-84372Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connectionspredis9.8 (v3.1)Critical
CVE-2026-35906An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 OS Command Injection Vulnerability-9.6 (v3.1)Critical
CVE-2026-8986Command Injection via Malicious OCPP Servermaxicharger single charger firmware9.5 (v4.0)Critical
CVE-2026-39932OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injectionopenemr9.4 (v4.0)Critical
CVE-2026-69256Flowise: Remote Code Execution Vulnerability in CSVAgentFlowise9.4 (v4.0)Critical
CVE-2018-25357Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.phpdolibarr erp/crm9.3 (v4.0)Critical
CVE-2024-9166TitanNit Web Control 2.01/Atemio 7600 - Remote Code ExecutionAtemio AM 520 HD Full HD Satellite Receiver9.3 (v4.0)Critical
CVE-2026-41939Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFlyCare Everywhere Gateway9.3 (v4.0)Critical
CVE-2026-44402Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgiSNMP Web Pro9.3 (v4.0)Critical
CVE-2026-53975OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/execOpenChamber9.3 (v4.0)Critical
CVE-2026-61498Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.phpflamingo9.3 (v4.0)Critical
CVE-2026-61511vBulletin 6.x - Remote Code ExecutionvBulletin9.3 (v4.0)Critical
CVE-2026-63766GPT-SoVITS 20250606v2pro OS Command Injection via webui.pyGPT-SoVITS9.3 (v4.0)Critical
CVE-2026-71921DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgiVigorSwitch G2540xs9.3 (v4.0)Critical
CVE-2026-71946D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRunDWR-M9619.3 (v4.0)Critical
CVE-2026-71947D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRunDWR-M9619.3 (v4.0)Critical
CVE-2026-71948D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRunDWR-M9619.3 (v4.0)Critical
CVE-2026-71955D-Link DWR-M961 Command Injection via /boafrm/formWscDWR-M9619.3 (v4.0)Critical
CVE-2026-71984MSI Radix AXE6600 v781521 Command Injection via urlfilterRadix AXE66009.3 (v4.0)Critical
CVE-2026-71992MSI Radix AXE6600 v781521 Command Injection via macfilterRadix AXE66009.3 (v4.0)Critical
CVE-2026-10042manga-image-translator RCE via Unsafe Pickle Deserialization in Share Modelmanga-image-translator9.2 (v4.0)Critical
CVE-2026-87930MaxSite CMS through 109.6 PHP Object Injection via ci_sessionMaxSite CMS9.2 (v4.0)Critical
CVE-2026-46621Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injectionyamcs9.1 (v3.1)Critical
CVE-2026-55511Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs executeSqlyamcs9.1 (v3.1)Critical
CVE-2026-58400GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formattercore-geonetwork9.1 (v3.1)Critical
CVE-2026-14602Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query ParameterRemote API9.0 (v3.1)Critical
CVE-2026-34612Kestra: Remote Code Execution via SQL Injectionkestra9.0 (v3.1)Critical
CVE-2026-62674Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCEomnigent9.0 (v3.1)Critical
CVE-2026-69251Flowise RCE via TypeORM DataSourceFlowise9.0 (v4.0)Critical
CVE-2026-43945FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration InjectionFUXA8.9 (v4.0)High
CVE-2026-73570zimbra collaboration suite Arbitrary Code Execution Vulnerabilityzimbra collaboration suite8.9 (v3.1)High
CVE-2017-6884Zyxel_ EMG2926 < V1.00(AAQT.4)b8 - OS Command Injectionemg2926 firmware8.8 (v3.1)High
CVE-2020-15874Command Injection-8.8 (v3.1)High
CVE-2021-22053Spring Cloud Netflix Hystrix Dashboard <2.2.10 - Remote Code Executionspring cloud netflix8.8 (v3.1)High
CVE-2021-32819Nodejs Squirrelly - Remote Code Executionsquirrelly8.8 (v3.1)High
CVE-2021-3577Motorola Baby Monitors - Remote Command Executionhalo+ camera firmware8.8 (v3.1)High
CVE-2026-34197Apache ActiveMQ - Remote Code Executionactivemq8.8 (v3.1)High
CVE-2026-35196Chamilo LMS has OS Command Injection via export_all_certificates actionchamilo lms8.8 (v3.1)High
CVE-2026-72875Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFiledokploy8.8 (v3.1)High
CVE-2021-47943TextPattern CMS 4.8.7 Remote Code Execution via File UploadTextPattern CMS8.7 (v4.0)High
CVE-2022-50944Aero CMS 0.0.1 PHP Code Injection via posts.phpAero CMS8.7 (v4.0)High
CVE-2025-34115OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.phpOP5 Monitor8.7 (v4.0)High
CVE-2025-71260BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCEfootprints8.7 (v4.0)High
CVE-2026-34228Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Writeemlog8.7 (v4.0)High
CVE-2026-34735Hytale Modding Vulnerable to Remote Code Execution via File Upload Bypass in FileControllerwiki8.7 (v4.0)High
CVE-2026-34792Endian Firewall /cgi-bin/logs_clamav.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34793Endian Firewall /cgi-bin/logs_firewall.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34794Endian Firewall /cgi-bin/logs_ids.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34795Endian Firewall /cgi-bin/logs_log.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34796Endian Firewall /cgi-bin/logs_openvpn.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34797Endian Firewall /cgi-bin/logs_smtp.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-67206Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Uploadwolfcms8.7 (v4.0)High
CVE-2026-71981Cypht < 2.12.2 PHP Object Injection RCE via back_query Parametercypht8.7 (v4.0)High
CVE-2026-76060OS Command Injection in PayRange APIZoneminder8.7 (v4.0)High
CVE-2026-76836AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group BypassAzuraCast8.7 (v4.0)High
CVE-2026-79756Nuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platformnuclio8.7 (v4.0)High
CVE-2026-85610OpenPanel before 2.3.0 Remote Code Execution via chart formulasopenpanel8.7 (v4.0)High
CVE-2024-20353adaptive security appliance software Denial of Service Vulnerabilityadaptive security appliance software8.6 (v3.1)High
CVE-2026-40187Authenticated RCE via Malicious eTemplate Upload in EGroupwareegroupware8.6 (v4.0)High
CVE-2026-42785OpenKM 6.3.12 Remote Code Execution via Administrative ScriptingOpenKM Community Edition8.6 (v4.0)High
CVE-2026-53804OTRS Community Edition OS Command Injection via PGP ConfigurationOTRS Community Edition8.6 (v4.0)High
CVE-2026-56703Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTOadminer8.6 (v4.0)High
CVE-2026-67599ClearOS 7.9 OS Command Injection via Log Viewer filter parameterClearOS8.6 (v4.0)High
CVE-2026-67608Telenia TVox 26.5.3 OS Command Injection via action_audio.phpTVox8.6 (v4.0)High
CVE-2026-71908DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_testVigorAP 918R8.6 (v4.0)High
CVE-2026-71913DrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgiVigorAP 918R8.6 (v4.0)High
CVE-2026-71918DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupActionVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71919DrayTek VigorSwitch Multiple Models OS Command Injection via sysrebootVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71931DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgradeVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-75123PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_postPLANET GS-4210-16P2S V38.6 (v4.0)High
CVE-2026-80214LibreNMS Virtualisation Discovery Module RCElibrenms8.6 (v4.0)High
CVE-2026-82692D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injectionDNS-340L8.6 (v4.0)High
CVE-2026-86733Snipe-IT before 8.7.0 Remote Code Execution via Backup Restoresnipe-it8.6 (v4.0)High
CVE-2026-22244OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCEopenmetadata8.5 (v4.0)High
CVE-2026-82690D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injectionDNS-327L8.5 (v4.0)High
CVE-2026-85222D-Link DNS-340L Add-On Center addon_center.cgi os command injectionDNS-340L8.5 (v4.0)High
CVE-2026-85224D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injectionDNS-320 ShareCenter8.5 (v4.0)High
CVE-2018-11776Apache Struts2 S2-057 - Remote Code Executionstruts8.1 (v3.1)High
CVE-2026-66738SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLiteSPIP7.7 (v4.0)High
CVE-2026-19913Kaltura HTML5 Video Player, html5lib library Improper Input Validation VulnerabilityKaltura HTML5 Video Player, html5lib library7.5 (v3.1)High
CVE-2026-34239Chamilo Authenticated Remote Code Executionchamilo-lms7.5 (v4.0)High
CVE-2026-36783Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to Denial of Service Vulnerability-7.5 (v3.1)High
CVE-2026-36796Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to Denial of Service Vulnerability-7.5 (v3.1)High
CVE-2026-46581mojarra Path Traversal Vulnerabilitymojarra7.5 (v3.1)High
CVE-2026-53599Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mocore7.5 (v3.1)High
CVE-2026-19771Baicells EG3661M LuCI Web luci os command injectionEG3661M7.3 (v4.0)High
CVE-2021-33544Geutebruck - Remote Command Injectiong-cam ebc-21107.2 (v3.1)High
CVE-2026-27891Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanismfacturascripts7.2 (v3.1)High
CVE-2025-71257BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypassfootprints itsm6.9 (v4.0)Medium
CVE-2026-19983GL.iNet XE3000 NAS Command Service gl_nas_sys os command injectionA13006.9 (v4.0)Medium
CVE-2026-45626Arcane: OS Command Injection in Volume Browser ListDirectory via path query parameterarcane6.3 (v3.1)Medium
CVE-2025-13786taosir WTCMS index.php fetch code injectionwtcms5.5 (v4.0)Medium
CVE-2025-13792Qualitor getResumo.php eval code injectionQualitor5.5 (v4.0)Medium
CVE-2026-19379EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injectionipTIME AX8004M5.5 (v4.0)Medium
CVE-2026-54611InstantCMS has Remote Code Execution in package installericms25.5 (v3.1)Medium
CVE-2026-82598SeaCMS Template search.php parseIf code injectionSeaCMS5.5 (v4.0)Medium
CVE-2026-9474yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injectionStudentManagementSystem5.5 (v4.0)Medium
CVE-2023-7299DataGear resolveSql sql injectiondatagear5.3 (v4.0)Medium
CVE-2026-19785francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injectionRosarioSIS5.3 (v4.0)Medium
CVE-2026-11408vertex-app vertex Log Viewer Endpoint LogMod.js os command injectionvertex2.1 (v4.0)Low
CVE-2026-8191Wavlink NU516U1 adm.cgi wifi_region os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-82678diem-project diem Administrative Console actions.class.php executeCommand os command injectiondiem2.0 (v4.0)Low

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-20CVE-2014-3206 , CVE-2017-12611 , CVE-2026-19912 , CVE-2026-34197 , CVE-2025-34115 , CVE-2026-19913 , CVE-2026-27891
CWE-22CVE-2026-19912 , CVE-2026-46581
CWE-73CVE-2026-19913
CWE-74CVE-2023-29827 , CVE-2025-13786 , CVE-2025-13792 , CVE-2026-82598 , CVE-2026-9474 , CVE-2023-7299 , CVE-2026-19785
CWE-77CVE-2026-72869 , CVE-2026-35847 , CVE-2020-15874 , CVE-2026-82692 , CVE-2026-82690 , CVE-2026-85222 , CVE-2026-85224 , CVE-2026-19771 , CVE-2026-19983 , CVE-2026-19379 , CVE-2026-11408 , CVE-2026-8191 , CVE-2026-82678
CWE-78CVE-2025-34030 , CVE-2025-34037 , CVE-2026-49869 , CVE-2026-42454 , CVE-2026-45629 , CVE-2026-72738 , CVE-2026-72869 , CVE-2026-72876 , CVE-2026-73294 , CVE-2020-28188 , CVE-2020-35476 , CVE-2021-32305 , CVE-2022-2486 , CVE-2022-2488 , CVE-2023-46359 , CVE-2026-12940 , CVE-2026-37281 , CVE-2026-53545 , CVE-2026-35906 , CVE-2026-8986 , CVE-2024-9166 , CVE-2026-53975 , CVE-2026-61498 , CVE-2026-63766 , CVE-2026-71921 , CVE-2026-71946 , CVE-2026-71947 , CVE-2026-71948 , CVE-2026-71955 , CVE-2026-71984 , CVE-2026-71992 , CVE-2026-73570 , CVE-2017-6884 , CVE-2021-3577 , CVE-2026-34197 , CVE-2026-35196 , CVE-2026-72875 , CVE-2025-34115 , CVE-2026-34792 , CVE-2026-34793 , CVE-2026-34794 , CVE-2026-34795 , CVE-2026-34796 , CVE-2026-34797 , CVE-2026-76060 , CVE-2026-79756 , CVE-2026-40187 , CVE-2026-53804 , CVE-2026-67599 , CVE-2026-67608 , CVE-2026-71908 , CVE-2026-71913 , CVE-2026-71918 , CVE-2026-71919 , CVE-2026-71931 , CVE-2026-75123 , CVE-2026-80214 , CVE-2026-82692 , CVE-2026-86733 , CVE-2026-82690 , CVE-2026-85222 , CVE-2026-85224 , CVE-2026-19771 , CVE-2021-33544 , CVE-2026-19983 , CVE-2026-45626 , CVE-2026-19379 , CVE-2026-11408 , CVE-2026-8191 , CVE-2026-82678
CWE-88CVE-2026-73294
CWE-89CVE-2026-38428 , CVE-2026-34612 , CVE-2026-9474 , CVE-2023-7299 , CVE-2026-19785
CWE-93CVE-2026-84372
CWE-94CVE-2026-55565 , CVE-2022-29078 , CVE-2026-46562 , CVE-2026-69256 , CVE-2018-25357 , CVE-2026-46621 , CVE-2026-55511 , CVE-2026-58400 , CVE-2026-14602 , CVE-2026-62674 , CVE-2026-69251 , CVE-2026-43945 , CVE-2021-22053 , CVE-2026-34197 , CVE-2022-50944 , CVE-2026-76836 , CVE-2026-85610 , CVE-2026-42785 , CVE-2026-56703 , CVE-2026-22244 , CVE-2026-66738 , CVE-2026-46581 , CVE-2025-13786 , CVE-2025-13792 , CVE-2026-54611 , CVE-2026-82598
CWE-95CVE-2026-46562 , CVE-2026-39932 , CVE-2026-61511 , CVE-2026-40187
CWE-120CVE-2026-36796
CWE-121CVE-2021-20038 , CVE-2026-36783
CWE-184CVE-2026-49869
CWE-200CVE-2021-32819
CWE-284CVE-2026-43945
CWE-285CVE-2026-34239
CWE-287CVE-2026-49869
CWE-288CVE-2026-43945
CWE-306CVE-2025-34115 , CVE-2025-71257
CWE-352CVE-2026-34228
CWE-434CVE-2026-44402 , CVE-2021-47943 , CVE-2026-34735 , CVE-2026-67206 , CVE-2026-53599 , CVE-2026-27891 , CVE-2026-54611
CWE-470CVE-2026-46562 , CVE-2026-58400
CWE-502CVE-2026-34838 , CVE-2026-3296 , CVE-2026-10042 , CVE-2026-87930 , CVE-2025-71260 , CVE-2026-71981
CWE-639CVE-2026-72876
CWE-641CVE-2026-46581
CWE-787CVE-2021-20038
CWE-835CVE-2024-20353
CWE-862CVE-2026-72876
CWE-863CVE-2026-43945 , CVE-2021-3577 , CVE-2026-76836
CWE-918CVE-2026-49869
CWE-1336CVE-2026-22244
CWE-1392CVE-2026-41939