What happened
Stack overflow in AllegroSoft RomPager cookie handling enables auth bypass, DoS, and RCE.
Affected versions
Unknown product: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
SploitusStack overflow in AllegroSoft RomPager cookie handling enables auth bypass, DoS, and RCE.luel-40132026-09-07T19:47:48VerifiedPoC-in-GitHub · luel-4013/misfortune-cookieThis interactive suite targets CVE-2014-9222 (Misfortune Cookie) in legacy RomPager web servers, alongside modular testing for CVE-2017-17215 (Huawei HG532 RCE), CVE-2018-14847 (MikroTik WinBox credential leak), and the CVE-2021-27101 / CVE-2021-27102 exploit chain (Accellion FTA).★ 0luel-40132026-09-07CandidatePoC-in-GitHub · donfanning/MIPS-CVE-2014-9222Lets have fun by digging into a Zyxel router firmware and MIPS Arch★ 0donfanning2019-08-14CandidatePoC-in-GitHub · mercul1ninna/MIPS-CVE-2014-9222Lets have fun by digging into a Zyxel router firmware and MIPS Arch★ 0mercul1ninna2022-07-14CandidateSource timeline
Discovered through SploitusView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.