Archive

Tech Analysis research archive

The research announcements originally published on the Tech Analysis website between 2014 and 2017, preserved at their original addresses.

Tech Analysis is no longer trading. This website is maintained as the personal profile and research archive of its founder, Chris Watts, who now works at CyberCX. Earlier research remains attributed to Tech Analysis as originally published.

Each entry links to a restored summary page at the original Tech Analysis address, the Cisco advisory and an archived copy of the original announcement. The full list of public vulnerability records credited to Chris Watts, including later CyberCX research, is on the research index.

Tech Analysis discovers cross-site request forgery vulnerability in Cisco SPA300 and SPA500 Series IP phones, CVE-2017-12271
Published . CVE-2017-12271: Cisco SPA300 and SPA500 Series IP phones.
Cross-site request forgery. Cisco advisory; archived original.
Tech Analysis discovers arbitrary code execution vulnerability in Cisco EPC2203 and DPC2203 cable modems, CVE-2016-1327
Published . CVE-2016-1327: Cisco DPC2203 and EPC2203 cable modems with digital voice.
Web server buffer overflow, remote code execution. Cisco advisory; archived original.
Tech Analysis discovers denial of service vulnerability in the Cisco DPQ3925 wireless residential gateway, CVE-2016-1326
Published . CVE-2016-1326: Cisco DPQ3925 wireless residential gateway.
Denial of service (device restart). Cisco advisory; archived original.
Tech Analysis discovers denial of service vulnerability in Cisco Small Business SPA3x/5x Series IP phones, CVE-2016-1469
Published . CVE-2016-1469: Cisco SPA300, SPA500 and SPA51x Series IP phones.
Denial of service (HTTP framework). Cisco advisory; archived original.
Tech Analysis discovers information disclosure vulnerability in the Cisco DPQ3925 wireless residential gateway, CVE-2015-6428
Published . CVE-2015-6428: Cisco DPQ3925 wireless residential gateway.
Information disclosure (HTTP server). Cisco advisory; archived original.
Tech Analysis discovers cross-site request forgery vulnerability in the Cisco DPQ3925 residential gateway, CVE-2015-6378
Published . CVE-2015-6378: Cisco DPQ3925 wireless residential gateway.
Cross-site request forgery. Cisco advisory; archived original.
Tech Analysis discovers Cisco IP phone firmware image upload vulnerability, CVE-2015-6403
Published . CVE-2015-6403: Cisco SPA30x, SPA50x and SPA51x Series IP phones.
Arbitrary firmware image load (insufficient integrity checks). Cisco advisory; archived original.
Tech Analysis finds unauthenticated remote dial vulnerability in Cisco SPA300 and SPA500 Series IP phones, CVE-2015-0670
Published . CVE-2015-0670: Cisco SPA300 and SPA500 Series IP phones.
Unauthenticated remote dial and audio-stream access. Cisco advisory; archived original.
Tech Analysis finds remote Cisco IP phone cross-site scripting vulnerability, CVE-2014-3313
Published . CVE-2014-3313: Cisco SPA300 and SPA500 Series IP phones.
Cross-site scripting in the web interface. Cisco advisory; archived original.
Tech Analysis finds local code execution vulnerability in Cisco SPA300 and SPA500 Series IP phones, CVE-2014-3312
Published . CVE-2014-3312: Cisco SPA300 and SPA500 Series IP phones.
Debug console authentication weakness, local code execution. Cisco advisory; archived original.
Tech Analysis finds remote code execution vulnerability in Cisco cable modems and gateways, CVE-2014-3306
Published . CVE-2014-3306: Cisco DPC/EPC 3010, 3212, 3825, 3925 and DPQ3925 cable modems and gateways.
Web server buffer overflow, remote code execution. Cisco advisory; archived original.