Remote Code Execution Vulnerability in AllegroSoft RomPager Used in Huawei Home Gateway Products
CVE-2014-9222
Currently unrated
Key Information:
- Vendor
Allegrosoft
- Status
- Vendor
- CVE Published:
- 24 December 2014
Badges
๐พ Exploit Exists๐ก Public PoC๐ฃ EPSS 63%
What is CVE-2014-9222?
AllegroSoft RomPager versions 4.34 and earlier, employed in various home gateway products, including those from Huawei, have a vulnerability that enables remote attackers to escalate privileges through a specially crafted cookie. This exploitation leverages memory corruption, giving unauthorized users potential access to sensitive system functionalities. It is critical for device manufacturers and users to address this issue to mitigate security risks associated with affected firmware.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
