On this page
Atomicorp WAF Rule 390904
Rule Summary
- Rule ID: 390904
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Possible Shell Command Attempt
- Observed CWEs: CWE-20 (1), CWE-22 (3), CWE-74 (1), CWE-77 (11), CWE-78 (20), CWE-79 (1), CWE-88 (1), CWE-89 (1), CWE-94 (3), CWE-200 (1), CWE-259 (1), CWE-285 (1), CWE-287 (1), CWE-306 (2), CWE-352 (1), CWE-434 (2), CWE-502 (1), CWE-798 (1), CWE-1392 (1)
- Revision: 15
- Rule severity: Critical (2)
- Request surfaces: Request arguments, JSON request data, SOAP request data
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “Possible Shell Command Attempt” in the request arguments, JSON request data, SOAP request data. denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2026-81735 | UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command Executi | UI-TARS-desktop | 10.0 (v4.0) | Critical |
| CVE-2026-44450 | Lumiverse: RCE via MCP stdio argument injection | Lumiverse | 9.9 (v3.1) | Critical |
| CVE-2026-48030 | Pheditor 2.0.1-2.0.3 - OS Command Injection | pheditor | 9.9 (v3.1) | Critical |
| CVE-2019-17270 | Yachtcontrol Webapplication 1.0 - Remote Command Injection | yachtcontrol | 9.8 (v3.1) | Critical |
| CVE-2021-28799 | QNAP HBS 3 - Broken Access Control | hybrid backup sync | 9.8 (v3.1) | Critical |
| CVE-2022-36553 | Hytec Inter HWL-2511-SS - Remote Command Execution | hwl-2511-ss firmware | 9.8 (v3.1) | Critical |
| CVE-2026-73042 | SiYuan before v3.7.4 Remote Code Execution via Menu Metadata | siyuan | 9.4 (v4.0) | Critical |
| CVE-2018-25357 | Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php | dolibarr erp/crm | 9.3 (v4.0) | Critical |
| CVE-2019-25687 | Pegasus CMS 1.0 Remote Code Execution via extra_fields.php | pegasus cms | 9.3 (v4.0) | Critical |
| CVE-2024-9166 | TitanNit Web Control 2.01/Atemio 7600 - Remote Code Execution | Atemio AM 520 HD Full HD Satellite Receiver | 9.3 (v4.0) | Critical |
| CVE-2026-27174 | MajorDoMo - Unauthenticated RCE | majordomo | 9.3 (v4.0) | Critical |
| CVE-2026-41939 | Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly | Care Everywhere Gateway | 9.3 (v4.0) | Critical |
| CVE-2026-64625 | AVideo before 29.0 OS Command Injection via execAsync | AVideo | 9.3 (v4.0) | Critical |
| CVE-2026-9385 | Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2020-24579 | D-Link DSL 2888a - Authentication Bypass/Remote Command Execution | dsl2888a firmware | 8.8 (v3.1) | High |
| CVE-2021-25082 | WordPress Popup Builder < 4.0.7 - Remote Code Execution | popup builder | 8.8 (v3.1) | High |
| CVE-2026-34228 | Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write | emlog | 8.7 (v4.0) | High |
| CVE-2026-63722 | ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.php | ICEcoder | 8.7 (v4.0) | High |
| CVE-2026-69096 | OpenWrt luci-app-dockerman Read ACL Remote Code Execution | luci | 8.7 (v4.0) | High |
| CVE-2026-42785 | OpenKM 6.3.12 Remote Code Execution via Administrative Scripting | OpenKM Community Edition | 8.6 (v4.0) | High |
| CVE-2026-53804 | OTRS Community Edition OS Command Injection via PGP Configuration | OTRS Community Edition | 8.6 (v4.0) | High |
| CVE-2026-63725 | sysPass FileBackupService Authenticated OS Command Injection via Backup Path | sysPass | 8.6 (v4.0) | High |
| CVE-2026-65711 | sysPass 3.2.11 Authenticated OS Command Injection via Backup Path | sysPass | 8.6 (v4.0) | High |
| CVE-2026-67608 | Telenia TVox 26.5.3 OS Command Injection via action_audio.php | TVox | 8.6 (v4.0) | High |
| CVE-2026-71919 | DrayTek VigorSwitch Multiple Models OS Command Injection via sysreboot | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-75123 | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_post | PLANET GS-4210-16P2S V3 | 8.6 (v4.0) | High |
| CVE-2026-82692 | D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection | DNS-340L | 8.6 (v4.0) | High |
| CVE-2026-82690 | D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection | DNS-327L | 8.5 (v4.0) | High |
| CVE-2026-82691 | D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection | DNS-320L | 8.5 (v4.0) | High |
| CVE-2026-85222 | D-Link DNS-340L Add-On Center addon_center.cgi os command injection | DNS-340L | 8.5 (v4.0) | High |
| CVE-2026-19900 | LB-LINK Routers - Unauthenticated Command Injection | bl-wr9000 firmware | 8.2 (v4.0) | High |
| CVE-2016-3081 | Apache S2-032 Struts - Remote Code Execution | struts | 8.1 (v3.0) | High |
| CVE-2017-12615 | Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1) | tomcat | 8.1 (v3.1) | High |
| CVE-2015-2824 | WordPress Plugin Simple Ads Manager - Multiple SQL Injections | simple ads manager | 7.5 (v2.0) | High |
| CVE-2026-18900 | H3C NX15 Backend RPC esps file.exec os command injection | NX15 | 7.3 (v4.0) | High |
| CVE-2026-27891 | Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism | facturascripts | 7.2 (v3.1) | High |
| CVE-2026-10821 | Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCE | Yoast SEO Premium | 6.6 (v3.1) | Medium |
| CVE-2017-9640 | Automated Logic WebCTRL 6.1 - Path Traversal / Arbitrary File Write | i-vu | 6.3 (v3.0) | Medium |
| CVE-2026-10214 | zhayujie chatgpt-on-wechat Bash Tool bash.py _get_safety_warning os command injection | chatgpt-on-wechat | 5.5 (v4.0) | Medium |
| CVE-2026-19379 | EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection | ipTIME AX8004M | 5.5 (v4.0) | Medium |
| CVE-2026-7220 | jackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injection | FastlyMCP | 5.5 (v4.0) | Medium |
| CVE-2015-2826 | WordPress Plugin Simple Ads Manager - Information Disclosure | simple ads manager | 5.3 (v3.0) | Medium |
| CVE-2026-16297 | Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import | Clearfy Cache | 4.1 (v3.1) | Medium |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.