← Vulnerability feed

Vulnerability record · CVE-2008-4128 · published 18 September 2008

CVE-2008-4128: Cisco IOS HTTP Administration CSRF allows arbitrary command execution

Cisco · Ios

The HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router is vulnerable to multiple cross-site request forgery flaws. An attacker can craft requests to the /level/15/exec/- URI (show privilege) and the /level/15/exec/-/configure/http URI (alias exec) that execute arbitrary commands on the device when an authenticated administrator is induced to visit a malicious page.

8.1 CVSS 3.1 High CISA KEV since 13 Jul 2026 EPSS 34% · top 1.7% CWE-352 · Cross-site request forgery
8.1CVSS 3.1 base score, v2 9.3
34%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
13References, 6 tagged exploit
24 Sep 2026Last modified by NVD

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is in CISA's KEV catalog with public exploit code and a high EPSS percentile, and successful exploitation yields arbitrary command execution on a network edge device, though it requires user interaction and the affected platform is an older IOS 12.4 release.

What it is

The HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router is vulnerable to multiple cross-site request forgery flaws. An attacker can craft requests to the /level/15/exec/- URI (show privilege) and the /level/15/exec/-/configure/http URI (alias exec) that execute arbitrary commands on the device when an authenticated administrator is induced to visit a malicious page.

Impact

An attacker can execute arbitrary IOS commands with the privileges of the logged-in administrator, including configuration changes and command aliasing, potentially leading to full device compromise or persistent manipulation of router behavior.

Attack surface

Reachable over the network through the router's HTTP administration interface; the CVSS vector indicates no privileges required but user interaction is required, meaning a victim administrator must be tricked into loading attacker-controlled content while authenticated.

Exploitation

CVE-2008-4128 is listed in CISA's Known Exploited Vulnerabilities catalog, and public exploit code exists in Exploit-DB (6476, 6477) and SecurityFocus references; EPSS shows a 30-day probability of 0.33917 (98.3rd percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Apply the vendor-recommended IOS update or mitigation per Cisco guidance for the affected 12.4 release on the 871 ISR; if no fix is available, discontinue use of the HTTP Administration interface.
  • Disable the HTTP/HTTPS administration server on affected routers where it is not strictly required.
  • Restrict management access to trusted management networks and require strong authentication; do not expose the HTTP admin interface to untrusted networks.
  • Follow CISA BOD 26-04 guidance and the CISA/NSA router hygiene advisory for hardening and triage of internet-exposed routers.
  • Verify compliance with CISA KEV required actions by the due date of 2026-07-16.

Detection

  • Monitor router and web/proxy logs for requests to /level/15/exec/- and /level/15/exec/-/configure/http URIs, especially with unexpected Referer headers.
  • Alert on unexpected IOS configuration changes, particularly alias exec commands or privilege-level changes, via configuration change monitoring or syslog.
  • Review HTTP administration access logs for requests originating from untrusted or external sources.
  • Correlate administrator browsing activity with concurrent router management requests to identify CSRF-style cross-origin access.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2008-4128 to the Known Exploited Vulnerabilities catalog on 13 July 2026 as "Cisco IOS Cross-Site Request Forgery Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 16 July 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-4128 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6738Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated remote attac…KEVEPSS 11%analysed8.8CVE-2017-6739Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. A remote attacker who knows the SN…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2008-4128), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.