Tech Analysis research archive
Tech Analysis discovers information disclosure vulnerability in the Cisco DPQ3925 wireless residential gateway, CVE-2015-6428
Tech Analysis is no longer trading. This website is maintained as the personal profile and research archive of its founder, Chris Watts, who now works at CyberCX. Earlier research remains attributed to Tech Analysis as originally published.
What was reported
On 17 December 2015 Cisco published an advisory for an information disclosure vulnerability in the HTTP server of the Cisco Model DPQ3925 8x4 DOCSIS 3.0 Wireless Residential Gateway with EDVA, version r1, assigned CVE-2015-6428. In Cisco's words, the flaw could allow an unauthenticated, remote attacker to access sensitive information located on the device via a crafted HTTP request. Cisco gave it a CVSS v2 base score of 5.0 and listed a workaround; the advisory was updated to revision 1.1 on 25 January 2016.
Tech Analysis announced the finding on this page on 1 September 2016, describing the device as the gateway supplied to customers of an Australian cable internet provider.
Primary sources
- Cisco: Cisco Model DPQ3925 Wireless Residential Gateway Information Disclosure Vulnerability (first published 17 December 2015)
- CVE-2015-6428 on cve.org
- Archived copy of the original Tech Analysis article (Internet Archive)
Attribution
Cisco's advisory states: "This vulnerability was reported to Cisco by Chris Watts of Tech Analysis. Cisco would like to thank him for reporting this issue to Cisco PSIRT."
See the full research index for all public vulnerability records credited to Chris Watts.