Tech Analysis research archive

Tech Analysis discovers information disclosure vulnerability in the Cisco DPQ3925 wireless residential gateway, CVE-2015-6428

Originally published on techanalysis.com.au by Tech Analysis on under the title "Discovered an information disclosure vulnerability in the Optus branded Cisco DPQ3925 8x4 DOCSIS 3.0 Wireless Residential Gateway - CVE-2015-6428"; first archived by the Internet Archive on . This page is a summary written to preserve the address and the record, not the original article text.

Tech Analysis is no longer trading. This website is maintained as the personal profile and research archive of its founder, Chris Watts, who now works at CyberCX. Earlier research remains attributed to Tech Analysis as originally published.

What was reported

On 17 December 2015 Cisco published an advisory for an information disclosure vulnerability in the HTTP server of the Cisco Model DPQ3925 8x4 DOCSIS 3.0 Wireless Residential Gateway with EDVA, version r1, assigned CVE-2015-6428. In Cisco's words, the flaw could allow an unauthenticated, remote attacker to access sensitive information located on the device via a crafted HTTP request. Cisco gave it a CVSS v2 base score of 5.0 and listed a workaround; the advisory was updated to revision 1.1 on 25 January 2016.

Tech Analysis announced the finding on this page on 1 September 2016, describing the device as the gateway supplied to customers of an Australian cable internet provider.

Primary sources

Attribution

Cisco's advisory states: "This vulnerability was reported to Cisco by Chris Watts of Tech Analysis. Cisco would like to thank him for reporting this issue to Cisco PSIRT."

See the full research index for all public vulnerability records credited to Chris Watts.