Web Hack List

Collected research

Misfortune Cookie -- TR-069 ACS Vulnerabilities in residential gateway routers

Misfortune Cookie Vulnerability

CVE-2014-9222 in the AllegroSoft RomPager embedded web server: a crafted HTTP cookie corrupts memory in the cookie handling code and makes the device treat the current session as administrative. One packet to a public IP takes over the gateway, and Check Point counted about 12 million exploitable residential routers across 200 device models and 189 countries.

Record

Document
Misfortune Cookie Vulnerability
Researcher
Check Point Software Technologies and @jifa
Published by
Misfortune Cookie Vulnerability by Check Point
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Check Point Software Technologies and @jifa, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .