cbcvebase.
CVE-2008-4128
published 2008-09-18

CVE-2008-4128: Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow…

PriorityP271medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-07-16
Exploited in the wild
EPSS
32.95%
98.2th percentile
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

Affected

1 ranges
VendorProductVersion rangeFixed in
ciscoios

Detection & IOCsextracted from sources · hover to see the quote

path/level/15/exec/-
path/level/15/exec/-/configure/http
commandshow privilege
commandalias exec
  • Monitor HTTP requests targeting Cisco IOS HTTP Administration URIs at privilege level 15 paths, specifically /level/15/exec/- and /level/15/exec/-/configure/http, which are the attack vectors for this CSRF vulnerability.
  • Threat actors scan for internet-exposed SNMP agents using common/default community strings as a precursor to exploiting Cisco device vulnerabilities including CVE-2008-4128; alert on SNMP Set-Requests from unexpected or spoofed source IPs.
  • Scans are run via proxies using SNMP Set-Requests from spoofed IP addresses containing OIDs that instruct the SNMP agent to copy device configuration to an attacker-controlled VPS or compromised FTP server; monitor for unexpected SNMP-triggered config transfers.
  • ·Vulnerability affects Cisco IOS 12.4 specifically on the 871 Integrated Services Router; scope is limited to this platform and version.
  • ·CISA KEV remediation deadline for federal agencies is 2026-07-16; organizations should prioritize patching or disabling the HTTP Administration component on affected Cisco IOS 12.4 devices.
  • ·If mitigations are unavailable, CISA guidance requires discontinuing use of the product; evaluate each asset's internet exposure per BOD 26-04 patching guidelines.

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck4.3MEDIUM
cisa4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.