CVE-2008-4128
published 2008-09-18CVE-2008-4128: Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow…
PriorityP271medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-07-16
Exploited in the wild
EPSS
32.95%
98.2th percentile
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor HTTP requests targeting Cisco IOS HTTP Administration URIs at privilege level 15 paths, specifically /level/15/exec/- and /level/15/exec/-/configure/http, which are the attack vectors for this CSRF vulnerability. ↗
- →Threat actors scan for internet-exposed SNMP agents using common/default community strings as a precursor to exploiting Cisco device vulnerabilities including CVE-2008-4128; alert on SNMP Set-Requests from unexpected or spoofed source IPs. ↗
- →Scans are run via proxies using SNMP Set-Requests from spoofed IP addresses containing OIDs that instruct the SNMP agent to copy device configuration to an attacker-controlled VPS or compromised FTP server; monitor for unexpected SNMP-triggered config transfers. ↗
- ·Vulnerability affects Cisco IOS 12.4 specifically on the 871 Integrated Services Router; scope is limited to this platform and version. ↗
- ·CISA KEV remediation deadline for federal agencies is 2026-07-16; organizations should prioritize patching or disabling the HTTP Administration component on affected Cisco IOS 12.4 devices. ↗
- ·If mitigations are unavailable, CISA guidance requires discontinuing use of the product; evaluate each asset's internet exposure per BOD 26-04 patching guidelines. ↗
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck4.3MEDIUM
cisa4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco IOS 12.4 Administration cross-site request forgery (EDB-6476 / XFDB-45226)
vuldb·2026-07-13·CVSS 4.3
CVE-2008-4128 [MEDIUM] Cisco IOS 12.4 Administration cross-site request forgery (EDB-6476 / XFDB-45226)
A vulnerability categorized as problematic has been discovered in Cisco IOS 12.4. The affected element is an unknown function of the component Administration. The manipulation results in cross-site request forgery.
This vulnerability is cataloged as CVE-2008-4128. The attack may be launched remotely. Furthermore, there is an exploit available.
GHSA
GHSA-6977-wjv6-r929: Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12
ghsa_unreviewed·2022-05-02
CVE-2008-4128 [HIGH] CWE-352 GHSA-6977-wjv6-r929: Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.
VulnCheck
Cisco IOS Cross-Site Request Forgery Vulnerability
vulncheck·2008·CVSS 4.3
CVE-2008-4128 [MEDIUM] CWE-352 Cisco IOS Cross-Site Request Forgery Vulnerability
Cisco IOS Cross-Site Request Forgery Vulnerability
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.
Affected: Cisco IOS Software
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inte
CISA
Cisco IOS Cross-Site Request Forgery Vulnerability
cisa·2026-07-13·CVSS 4.3
CVE-2008-4128 [MEDIUM] CWE-352 Cisco IOS Cross-Site Request Forgery Vulnerability
Vulnerability: Cisco IOS Cross-Site Request Forgery Vulnerability
Affected: Cisco IOS
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's
No detection rules found.
http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.htmlhttp://www.securityfocus.com/bid/31218https://exchange.xforce.ibmcloud.com/vulnerabilities/45226https://www.exploit-db.com/exploits/6476https://www.exploit-db.com/exploits/6477http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.htmlhttp://www.securityfocus.com/bid/31218https://exchange.xforce.ibmcloud.com/vulnerabilities/45226https://www.exploit-db.com/exploits/6476https://www.exploit-db.com/exploits/6477https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDFhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2008-4128https://www.cisco.com/c/en/us/obsolete/ios-nx-os-software/cisco-ios-software-releases-12-4-mainline.html
2008-09-18
Published
2026-07-13
Added to CISA KEV
Exploited in the wild