Vulnerability record · CVE-2008-4128 · published 18 September 2008
CVE-2008-4128: Cisco IOS HTTP Administration CSRF allows arbitrary command execution
Cisco · Ios
The HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router is vulnerable to multiple cross-site request forgery flaws. An attacker can craft requests to the /level/15/exec/- URI (show privilege) and the /level/15/exec/-/configure/http URI (alias exec) that execute arbitrary commands on the device when an authenticated administrator is induced to visit a malicious page.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Automated analysis
high priorityThe flaw is in CISA's KEV catalog with public exploit code and a high EPSS percentile, and successful exploitation yields arbitrary command execution on a network edge device, though it requires user interaction and the affected platform is an older IOS 12.4 release.
What it is
The HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router is vulnerable to multiple cross-site request forgery flaws. An attacker can craft requests to the /level/15/exec/- URI (show privilege) and the /level/15/exec/-/configure/http URI (alias exec) that execute arbitrary commands on the device when an authenticated administrator is induced to visit a malicious page.
Impact
An attacker can execute arbitrary IOS commands with the privileges of the logged-in administrator, including configuration changes and command aliasing, potentially leading to full device compromise or persistent manipulation of router behavior.
Attack surface
Reachable over the network through the router's HTTP administration interface; the CVSS vector indicates no privileges required but user interaction is required, meaning a victim administrator must be tricked into loading attacker-controlled content while authenticated.
Exploitation
CVE-2008-4128 is listed in CISA's Known Exploited Vulnerabilities catalog, and public exploit code exists in Exploit-DB (6476, 6477) and SecurityFocus references; EPSS shows a 30-day probability of 0.33917 (98.3rd percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the vendor-recommended IOS update or mitigation per Cisco guidance for the affected 12.4 release on the 871 ISR; if no fix is available, discontinue use of the HTTP Administration interface.
- Disable the HTTP/HTTPS administration server on affected routers where it is not strictly required.
- Restrict management access to trusted management networks and require strong authentication; do not expose the HTTP admin interface to untrusted networks.
- Follow CISA BOD 26-04 guidance and the CISA/NSA router hygiene advisory for hardening and triage of internet-exposed routers.
- Verify compliance with CISA KEV required actions by the due date of 2026-07-16.
Detection
- Monitor router and web/proxy logs for requests to /level/15/exec/- and /level/15/exec/-/configure/http URIs, especially with unexpected Referer headers.
- Alert on unexpected IOS configuration changes, particularly alias exec commands or privilege-level changes, via configuration change monitoring or syslog.
- Review HTTP administration access logs for requests originating from untrusted or external sources.
- Correlate administrator browsing activity with concurrent router management requests to identify CSRF-style cross-origin access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2008-4128 to the Known Exploited Vulnerabilities catalog on 13 July 2026 as "Cisco IOS Cross-Site Request Forgery Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 16 July 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-4128 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-4128), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.