On this page

Atomicorp WAF Rule 390904

Rule Summary

Description

This rule detects behavior identified by its current alert as “Possible Shell Command Attempt” in the request arguments, JSON request data, SOAP request data. denies matching traffic with HTTP status 403.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2026-81735UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command ExecutiUI-TARS-desktop10.0 (v4.0)Critical
CVE-2026-44450Lumiverse: RCE via MCP stdio argument injectionLumiverse9.9 (v3.1)Critical
CVE-2026-48030Pheditor 2.0.1-2.0.3 - OS Command Injectionpheditor9.9 (v3.1)Critical
CVE-2019-17270Yachtcontrol Webapplication 1.0 - Remote Command Injectionyachtcontrol9.8 (v3.1)Critical
CVE-2021-28799QNAP HBS 3 - Broken Access Controlhybrid backup sync9.8 (v3.1)Critical
CVE-2022-36553Hytec Inter HWL-2511-SS - Remote Command Executionhwl-2511-ss firmware9.8 (v3.1)Critical
CVE-2026-73042SiYuan before v3.7.4 Remote Code Execution via Menu Metadatasiyuan9.4 (v4.0)Critical
CVE-2018-25357Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.phpdolibarr erp/crm9.3 (v4.0)Critical
CVE-2019-25687Pegasus CMS 1.0 Remote Code Execution via extra_fields.phppegasus cms9.3 (v4.0)Critical
CVE-2024-9166TitanNit Web Control 2.01/Atemio 7600 - Remote Code ExecutionAtemio AM 520 HD Full HD Satellite Receiver9.3 (v4.0)Critical
CVE-2026-27174MajorDoMo - Unauthenticated RCEmajordomo9.3 (v4.0)Critical
CVE-2026-41939Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFlyCare Everywhere Gateway9.3 (v4.0)Critical
CVE-2026-64625AVideo before 29.0 OS Command Injection via execAsyncAVideo9.3 (v4.0)Critical
CVE-2026-9385Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2020-24579D-Link DSL 2888a - Authentication Bypass/Remote Command Executiondsl2888a firmware8.8 (v3.1)High
CVE-2021-25082WordPress Popup Builder < 4.0.7 - Remote Code Executionpopup builder8.8 (v3.1)High
CVE-2026-34228Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Writeemlog8.7 (v4.0)High
CVE-2026-63722ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.phpICEcoder8.7 (v4.0)High
CVE-2026-69096OpenWrt luci-app-dockerman Read ACL Remote Code Executionluci8.7 (v4.0)High
CVE-2026-42785OpenKM 6.3.12 Remote Code Execution via Administrative ScriptingOpenKM Community Edition8.6 (v4.0)High
CVE-2026-53804OTRS Community Edition OS Command Injection via PGP ConfigurationOTRS Community Edition8.6 (v4.0)High
CVE-2026-63725sysPass FileBackupService Authenticated OS Command Injection via Backup PathsysPass8.6 (v4.0)High
CVE-2026-65711sysPass 3.2.11 Authenticated OS Command Injection via Backup PathsysPass8.6 (v4.0)High
CVE-2026-67608Telenia TVox 26.5.3 OS Command Injection via action_audio.phpTVox8.6 (v4.0)High
CVE-2026-71919DrayTek VigorSwitch Multiple Models OS Command Injection via sysrebootVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-75123PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_postPLANET GS-4210-16P2S V38.6 (v4.0)High
CVE-2026-82692D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injectionDNS-340L8.6 (v4.0)High
CVE-2026-82690D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injectionDNS-327L8.5 (v4.0)High
CVE-2026-82691D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injectionDNS-320L8.5 (v4.0)High
CVE-2026-85222D-Link DNS-340L Add-On Center addon_center.cgi os command injectionDNS-340L8.5 (v4.0)High
CVE-2026-19900LB-LINK Routers - Unauthenticated Command Injectionbl-wr9000 firmware8.2 (v4.0)High
CVE-2016-3081Apache S2-032 Struts - Remote Code Executionstruts8.1 (v3.0)High
CVE-2017-12615Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1)tomcat8.1 (v3.1)High
CVE-2015-2824WordPress Plugin Simple Ads Manager - Multiple SQL Injectionssimple ads manager7.5 (v2.0)High
CVE-2026-18900H3C NX15 Backend RPC esps file.exec os command injectionNX157.3 (v4.0)High
CVE-2026-27891Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanismfacturascripts7.2 (v3.1)High
CVE-2026-10821Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCEYoast SEO Premium6.6 (v3.1)Medium
CVE-2017-9640Automated Logic WebCTRL 6.1 - Path Traversal / Arbitrary File Writei-vu6.3 (v3.0)Medium
CVE-2026-10214zhayujie chatgpt-on-wechat Bash Tool bash.py _get_safety_warning os command injectionchatgpt-on-wechat5.5 (v4.0)Medium
CVE-2026-19379EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injectionipTIME AX8004M5.5 (v4.0)Medium
CVE-2026-7220jackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injectionFastlyMCP5.5 (v4.0)Medium
CVE-2015-2826WordPress Plugin Simple Ads Manager - Information Disclosuresimple ads manager5.3 (v3.0)Medium
CVE-2026-16297Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings ImportClearfy Cache4.1 (v3.1)Medium

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-20CVE-2026-27891
CWE-22CVE-2019-25687 , CVE-2021-25082 , CVE-2017-9640
CWE-74CVE-2026-10821
CWE-77CVE-2022-36553 , CVE-2026-9385 , CVE-2026-82692 , CVE-2026-82690 , CVE-2026-82691 , CVE-2026-85222 , CVE-2016-3081 , CVE-2026-18900 , CVE-2026-10214 , CVE-2026-19379 , CVE-2026-7220
CWE-78CVE-2026-48030 , CVE-2019-17270 , CVE-2024-9166 , CVE-2026-64625 , CVE-2026-9385 , CVE-2026-69096 , CVE-2026-53804 , CVE-2026-63725 , CVE-2026-65711 , CVE-2026-67608 , CVE-2026-71919 , CVE-2026-75123 , CVE-2026-82692 , CVE-2026-82690 , CVE-2026-82691 , CVE-2026-85222 , CVE-2026-18900 , CVE-2026-10214 , CVE-2026-19379 , CVE-2026-7220
CWE-79CVE-2026-73042
CWE-88CVE-2026-44450
CWE-89CVE-2015-2824
CWE-94CVE-2018-25357 , CVE-2026-27174 , CVE-2026-42785
CWE-200CVE-2015-2826
CWE-259CVE-2026-19900
CWE-285CVE-2021-28799
CWE-287CVE-2020-24579
CWE-306CVE-2026-81735 , CVE-2026-63722
CWE-352CVE-2026-34228
CWE-434CVE-2017-12615 , CVE-2026-27891
CWE-502CVE-2026-16297
CWE-798CVE-2026-19900
CWE-1392CVE-2026-41939