logo

Please Apply Our 10 Year-Old Patch: The Dismal State of Embedded Device Security

ID: 93b32c86-fac8-5307-8ef6-769d4a2047db

STIX ID: report--93b32c86-fac8-5307-8ef6-769d4a2047db

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2014-12-22

Date Updated: 2026-05-05

Author: Paul Roberts

...
...

The article details the “Misfortune Cookie” vulnerabilities (CVE-2014-9222 and CVE-2014-9223) in the Rom Pager embedded web server found in an estimated 12 million consumer broadband routers from vendors such as Linksys, D-Link, Huawei, TP-Link, ZTE and Edimax; it describes how specially crafted HTTP cookies can grant administrative privileges to attackers (enabling DNS hijacking or botnet enlistment) and highlights that although a patch exists, many manufacturers did not distribute firmware updates, leaving large numbers of devices vulnerable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.