CVE-2014-9222

EXPLOITED

Allegro Software RomPager

Title source: metasploit

Description

AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the "Misfortune Cookie" vulnerability.

Exploits (5)

nomisec WRITEUP 6 stars
by BenChaliah · poc
https://github.com/BenChaliah/MIPS-CVE-2014-9222
nomisec WRITEUP
by mercul1ninna · poc
https://github.com/mercul1ninna/MIPS-CVE-2014-9222
nomisec WRITEUP
by donfanning · poc
https://github.com/donfanning/MIPS-CVE-2014-9222
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/allegro_rompager_auth_bypass.rb
metasploit SCANNER
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/allegro_rompager_misfortune_cookie.rb

Scores

EPSS 0.8645
EPSS Percentile 99.4%

Details

VulnCheck KEV 2017-04-11
CWE
CWE-17
Status published
Products (1)
allegrosoft/rompager < 4.07
Published Dec 24, 2014
Tracked Since Feb 18, 2026