Tech Analysis research archive

Tech Analysis discovers cross-site request forgery vulnerability in the Cisco DPQ3925 residential gateway, CVE-2015-6378

Originally published on techanalysis.com.au by Tech Analysis on under the title "Chris Watts Tech Analysis discovered a CSRF vulnerability in the Optus branded Cisco DPQ3925 DOCSIS 3.0 Wireless Residential Gateway - CVE-2015-6378"; first archived by the Internet Archive on . This page is a summary written to preserve the address and the record, not the original article text.

Tech Analysis is no longer trading. This website is maintained as the personal profile and research archive of its founder, Chris Watts, who now works at CyberCX. Earlier research remains attributed to Tech Analysis as originally published.

What was reported

On 8 December 2015 Cisco published an advisory for a cross-site request forgery (CSRF) vulnerability in the Cisco Model DPQ3925 8x4 DOCSIS 3.0 Wireless Residential Gateway with EDVA, assigned CVE-2015-6378. In Cisco's words, insufficient CSRF protections could allow an unauthenticated, remote attacker to perform actions as a logged-in user by convincing that user to follow a malicious link or visit an attacker-controlled website. Cisco gave it a CVSS v2 base score of 4.3 and stated that it had not released software updates for the issue. The researcher credit was added in revision 1.1 of the advisory on 25 January 2016.

Tech Analysis announced the finding on this page on 22 June 2016, describing the device as the gateway supplied to customers of an Australian cable internet provider and the practical impact as the ability to change the gateway's DNS settings through a forged request.

Primary sources

Attribution

Cisco's advisory states: "This vulnerability was reported to Cisco by Chris Watts of Tech Analysis. Cisco would like to thank him for reporting this vulnerability to Cisco PSIRT."

See the full research index for all public vulnerability records credited to Chris Watts.