What happened
Stack overflow in AllegroSoft RomPager cookie handling enables auth bypass, DoS, and RCE.
Affected versions
Unknown product: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 43414Huawei Router HG532 - Arbitrary Command Executionanonymous2017-12-25VerifiedSploitusStack overflow in AllegroSoft RomPager cookie handling enables auth bypass, DoS, and RCE.luel-40132026-09-07T19:47:48VerifiedPoC-in-GitHub · luel-4013/misfortune-cookieThis interactive suite targets CVE-2014-9222 (Misfortune Cookie) in legacy RomPager web servers, alongside modular testing for CVE-2017-17215 (Huawei HG532 RCE), CVE-2018-14847 (MikroTik WinBox credential leak), and the CVE-2021-27101 / CVE-2021-27102 exploit chain (Accellion FTA).★ 0luel-40132026-09-07CandidatePoC-in-GitHub · 1337g/CVE-2017-17215CVE-2017-17215 HuaWei Router RCE (NOT TESTED)★ 261337g2017-12-25CandidatePoC-in-GitHub · wilfred-wulbou/HG532d-RCE-ExploitA Remote Code Execution (RCE) exploit for Huawei HG532d based on CVE-2017-17215 vulnerability. Modded from original PoC code from exploit-db.com★ 9wilfred-wulbou2020-11-17CandidatePoC-in-GitHub · ltfafei/HuaWei_Route_HG532_RCE_CVE-2017-17215POCsuite与goland实现华为HG532路由器命令注入CVE-2017-17215 POC★ 0ltfafei2022-11-02CandidateSource timeline
Discovered through Exploit-DBView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.