Archive
Tech Analysis research archive
The research announcements originally published on the Tech Analysis website between 2014 and 2017, preserved at their original addresses.
Tech Analysis is no longer trading. This website is maintained as the personal profile and research archive of its founder, Chris Watts, who now works at CyberCX. Earlier research remains attributed to Tech Analysis as originally published.
Each entry links to a restored summary page at the original Tech Analysis address, the Cisco advisory and an archived copy of the original announcement. The full list of public vulnerability records credited to Chris Watts, including later CyberCX research, is on the research index.
- Tech Analysis discovers cross-site request forgery vulnerability in Cisco SPA300 and SPA500 Series IP phones, CVE-2017-12271
- Cross-site request forgery. Cisco advisory; archived original.
- Tech Analysis discovers arbitrary code execution vulnerability in Cisco EPC2203 and DPC2203 cable modems, CVE-2016-1327
- Web server buffer overflow, remote code execution. Cisco advisory; archived original.
- Tech Analysis discovers denial of service vulnerability in the Cisco DPQ3925 wireless residential gateway, CVE-2016-1326
- Denial of service (device restart). Cisco advisory; archived original.
- Tech Analysis discovers denial of service vulnerability in Cisco Small Business SPA3x/5x Series IP phones, CVE-2016-1469
- Denial of service (HTTP framework). Cisco advisory; archived original.
- Tech Analysis discovers information disclosure vulnerability in the Cisco DPQ3925 wireless residential gateway, CVE-2015-6428
- Information disclosure (HTTP server). Cisco advisory; archived original.
- Tech Analysis discovers cross-site request forgery vulnerability in the Cisco DPQ3925 residential gateway, CVE-2015-6378
- Cross-site request forgery. Cisco advisory; archived original.
- Tech Analysis discovers Cisco IP phone firmware image upload vulnerability, CVE-2015-6403
- Arbitrary firmware image load (insufficient integrity checks). Cisco advisory; archived original.
- Tech Analysis finds unauthenticated remote dial vulnerability in Cisco SPA300 and SPA500 Series IP phones, CVE-2015-0670
- Unauthenticated remote dial and audio-stream access. Cisco advisory; archived original.
- Tech Analysis finds remote Cisco IP phone cross-site scripting vulnerability, CVE-2014-3313
- Cross-site scripting in the web interface. Cisco advisory; archived original.
- Tech Analysis finds local code execution vulnerability in Cisco SPA300 and SPA500 Series IP phones, CVE-2014-3312
- Debug console authentication weakness, local code execution. Cisco advisory; archived original.
- Tech Analysis finds remote code execution vulnerability in Cisco cable modems and gateways, CVE-2014-3306
- Web server buffer overflow, remote code execution. Cisco advisory; archived original.