Sploitus

CVE-2014-9222

17 known exploits for CVE-2014-9222

AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the "Misfortune Cookie" vulnerability.

Affected products
Rompager
Allegrosoft Rompager
≀ 4.07
Fix
Available
CVSS 2.0
10.0 HIGH
EPSS
63.7% (99th percentile)
Weakness
CWE-17
NVD status
Modified
Published
2014-12-24
CVE-2014-9222 at NVD
Authoritative description, scoring and affected products

17 known exploits for CVE-2014-9222

Proof-of-concept code and exploit modules indexed by Sploitus

MIPS-CVE-2014-9222
2026-09-07 KitPloitKITPLOIT
misfortune-cookie
2026-09-07 luel-4013GITHUB
MIPS-CVE-2014-9222
2026-09-06 KitPloitKITPLOIT
python-hacklib
2026-09-06 KitPloitKITPLOIT
πŸ“„ AudioCodes Fax/IVR Appliance 2.6.23 File Upload / Code Execution / Privilege Escalation
2025-11-20 Pierre KimPACKETSTORMHTML
Allegro Software RomPager Misfortune Cookie (CVE-2014-9222) Scanner
2024-09-01 Jon Hart, Lior Oppenheim, metasploit.comPACKETSTORMRuby
Allegro Software RomPager Misfortune Cookie (CVE-2014-9222) Authentication Bypass
2024-08-31 Jon Hart, Lior Oppenheim, Jan Trencansky, metasploit.comPACKETSTORMRuby
Eir’s D1000 Modem Is Wide Open To Being Hacked.
2017-12-28 RootSEEBUGRuby
hacklib - Pentesting, Port Scanning, and Logging in anywhere with Python
2016-10-05 KitPloitKITPLOIT
RomPager 4.34 - Misfortune Cookie Router Authentication Bypass
2016-04-27 Milad DoorbashZDT
RomPager 4.34 (Multiple Router Vendors) - Misfortune Cookie Authentication Bypass
2016-04-27 Milad DoorbashEXPLOITPACK
RomPager 4.34 Authentication Bypass
2016-04-27 Milad DoorbashPACKETSTORM
Allegro v4.34 ζƒι™ζε‡ζΌζ΄ž
2015-05-07 RootSEEBUG
Immunity Canvas: CVE_2014_9222
2014-12-24 Immunity CanvasCANVAS
CVE-2014-9222
2014-12-24 mitreUNKNOWN
Allegro Software RomPager 'Misfortune Cookie' (CVE-2014-9222) Scanner
2014-12-17 Jon Hart <jon_hart@rapid7.com>, Lior OppenheimMETASPLOITRuby
Allegro Software RomPager 'Misfortune Cookie' (CVE-2014-9222) Authentication Bypass
2014-12-17 Jon Hart <jon_hart@rapid7.com>, Jan Trencansky <jan.trencansky@gmail.com>, Lior OppenheimMETASPLOITRuby