← Vulnerability feed

Vulnerability record · CVE-2014-9222 · published 24 December 2014

CVE-2014-9222: AllegroSoft RomPager cookie handling memory corruption

Allegrosoft · Rompager

RomPager 4.34 and earlier, embedded in Huawei Home Gateway products and other vendor devices, mishandles a crafted cookie in a way that corrupts memory. Because the flaw is remotely reachable and yields full control of the affected device, it is a serious risk for internet-exposed routers and gateways.

10.0 CVSS 2.0 High EPSS 64% · top 0.8% CWE-17 · CWE-17
10.0CVSS 2.0 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the "Misfortune Cookie" vulnerability.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with full impact on widely deployed embedded gateways, backed by a CVSS 10.0 and very high EPSS.

What it is

RomPager 4.34 and earlier, embedded in Huawei Home Gateway products and other vendor devices, mishandles a crafted cookie in a way that corrupts memory. Because the flaw is remotely reachable and yields full control of the affected device, it is a serious risk for internet-exposed routers and gateways.

Impact

A remote attacker can gain privileges on the device, effectively taking full control of confidentiality, integrity and availability. On a home gateway this means the attacker can alter routing, intercept traffic or use the device as a foothold.

Attack surface

Reached over the network via HTTP requests to the embedded web management interface, with no authentication and no user interaction required per the AV:N/AC:L/Au:N vector. Any device exposing the vulnerable RomPager service is a candidate.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.637, 99th percentile) and public technical descriptions and advisories exist, indicating mature public knowledge of the flaw.

What to do

  • Apply vendor firmware updates for affected Huawei Home Gateway and other RomPager-based devices; where no fix exists, replace the device.
  • Disable or restrict remote access to the embedded web management interface, especially from the internet.
  • Place affected devices behind a firewall and block inbound access to their management ports.
  • Inventory embedded devices running RomPager and track them for firmware support status.
  • Segment IoT and gateway devices from sensitive internal networks.

Detection

  • Monitor HTTP requests to embedded device management interfaces for malformed or unusually long Cookie headers.
  • Alert on unexpected configuration changes, new admin accounts or routing changes on gateway devices.
  • Watch for outbound connections from gateway devices to unknown external hosts.
  • Use network scanning to identify devices still exposing RomPager-based web interfaces.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-9222 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2014-9222), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.