CVE-2008-4128 KEV EXPLOIT
8.1
HIGH · CVSS 3.1 · EPSS 33.9% (pctl 98)
Patch first
On CISA KEV — known exploited in the wild, due 2026-07-16.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.
Scoring
| CVSS | 8.1 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
| EPSS | 33.87% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-352 |
| On CISA KEV | yes — remediate by 2026-07-16 |
| Public exploit | yes |
| Published | 2008-09-18 |
| Last modified | 2026-09-24 |
CISA KEV
| Name | Cisco IOS Cross-Site Request Forgery Vulnerability |
|---|---|
| Added | 2026-07-13 |
| Due | 2026-07-16 |
| Vendor / product | Cisco / IOS |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| cisco | 871 integrated services router |
| cisco | ios |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Cisco Router - HTTP Administration Cross-Site Request Forgery / Command Execution (1) | 2008-09-17 |
References
- http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.html
- http://www.securityfocus.com/bid/31218
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45226
- https://www.exploit-db.com/exploits/6476
- https://www.exploit-db.com/exploits/6477
- http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.html
- http://www.securityfocus.com/bid/31218
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45226
- https://www.exploit-db.com/exploits/6476
- https://www.exploit-db.com/exploits/6477
- https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2008-4128
- https://www.cisco.com/c/en/us/obsolete/ios-nx-os-software/cisco-ios-software-releases-12-4-mainline.html
→ the Explorer · watch your stack · NVD