Tech Analysis research archive
Tech Analysis discovers cross-site request forgery vulnerability in the Cisco DPQ3925 residential gateway, CVE-2015-6378
Tech Analysis is no longer trading. This website is maintained as the personal profile and research archive of its founder, Chris Watts, who now works at CyberCX. Earlier research remains attributed to Tech Analysis as originally published.
What was reported
On 8 December 2015 Cisco published an advisory for a cross-site request forgery (CSRF) vulnerability in the Cisco Model DPQ3925 8x4 DOCSIS 3.0 Wireless Residential Gateway with EDVA, assigned CVE-2015-6378. In Cisco's words, insufficient CSRF protections could allow an unauthenticated, remote attacker to perform actions as a logged-in user by convincing that user to follow a malicious link or visit an attacker-controlled website. Cisco gave it a CVSS v2 base score of 4.3 and stated that it had not released software updates for the issue. The researcher credit was added in revision 1.1 of the advisory on 25 January 2016.
Tech Analysis announced the finding on this page on 22 June 2016, describing the device as the gateway supplied to customers of an Australian cable internet provider and the practical impact as the ability to change the gateway's DNS settings through a forged request.
Primary sources
- Cisco: Cisco Residential Gateway Devices Cross-Site Request Forgery Vulnerability (first published 8 December 2015)
- CVE-2015-6378 on cve.org
- Archived copy of the original Tech Analysis article (Internet Archive)
Attribution
Cisco's advisory states: "This vulnerability was reported to Cisco by Chris Watts of Tech Analysis. Cisco would like to thank him for reporting this vulnerability to Cisco PSIRT."
See the full research index for all public vulnerability records credited to Chris Watts.