peter bassill · operator
$ cve CVE-2008-4128 JSON

CVE-2008-4128 KEV EXPLOIT

8.1
HIGH · CVSS 3.1 · EPSS 33.9% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2026-07-16.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

Scoring

CVSS8.1 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS33.87% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-352
On CISA KEVyes — remediate by 2026-07-16
Public exploityes
Published2008-09-18
Last modified2026-09-24

CISA KEV

NameCisco IOS Cross-Site Request Forgery Vulnerability
Added2026-07-13
Due2026-07-16
Vendor / productCisco / IOS
Ransomware usenone reported

Affected (2)

VendorProduct
cisco871 integrated services router
ciscoios

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD