CVE-2015-6401 describes an authentication bypass vulnerability in Cisco EPC3928 devices running specific EDVA firmware versions (5.5.10, 5.5.11, and 5.7.1). This flaw allows remote attackers to execute administrative functions through crafted HTTP requests. With a CVSS score of 7.5, it poses a high severity risk due to its network-based attack vector, low complexity, and potential for partial compromise of confidentiality, integrity, and availability. While not in CISA's KEV catalog, exploit code is publicly available on ExploitDB, and it has garnered significant community discussion and media coverage, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.5.10CPE matchmatch criteria | cpe:2.3:o:cisco:epc3928_docsis_3.0_8x4_wireless_residential_gateway_with_embedded_digital_voice_adapter:5.5.10:*:*:*:*:*:*:* | ||
5.5.11CPE matchmatch criteria | cpe:2.3:o:cisco:epc3928_docsis_3.0_8x4_wireless_residential_gateway_with_embedded_digital_voice_adapter:5.5.11:*:*:*:*:*:*:* | ||
5.7.1CPE matchmatch criteria | cpe:2.3:o:cisco:epc3928_docsis_3.0_8x4_wireless_residential_gateway_with_embedded_digital_voice_adapter:5.7.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.