CVE-2008-4128

● KEV MEDIUM ⚠ Exploit

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary c...

Affects 2 products across 1 vendor.

BCS8.28
CVSS 3.14.3
EPSS33.0%
Percentile98th
PatchUnknown
KEV Added2026-07-13
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, requires user interaction, impact contained to the vulnerable component, no integrity impact, no availability impact.
CWE Weakness Definitions
CWE-352: Cross-Site Request Forgery (CSRF)

Web application does not verify that a request was intentionally sent by the authenticated user.

Related Attack Patterns (CAPEC)
CAPEC-462 Cross-Domain Search Timing
via CWE-352
CAPEC-467 Cross Site Identification
via CWE-352
CAPEC-62 Cross Site Request Forgery
via CWE-352
CAPEC-111 JSON Hijacking (aka JavaScript Hijacking)
via CWE-352

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component of Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands.

BSID: BS-2008-GLOBAL-156892-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2008-4128?
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component of Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands.
What is the CVSS score for CVE-2008-4128?
CVE-2008-4128 has CVSS 4.3 (Medium). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N. EPSS: 33.0%.
Is CVE-2008-4128 actively exploited?
Yes. CVE-2008-4128 is in the CISA KEV catalog (added 2026-07-13). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2008-4128?
Priority: IMMEDIATE.
What systems are affected by CVE-2008-4128?
CVE-2008-4128 affects: Cisco, Cisco.
Vulnerability Details
CVE IDCVE-2008-4128
BSIDBS-2008-GLOBAL-156892-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Published2008-09-18
Last Modified2026-07-13
ICS Relevance85%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Remote attackers can exploit these vulnerabilities by sending specially crafted requests to the /level/15/exec/- and /level/15/exec/-/configure/http URIs, potentially leading to unauthorized command execution.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Cisco Ios
Cisco 871 Integrated Services Router
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 6519 Days
CISA KEV● Active Exploitation Confirmed (added 2026-07-13)
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Cisco
CVE-2025-20393 10.0 A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for ... CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2003-0732 10.0 CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the gues... CVE-2004-0308 10.0 Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(... CVE-2007-5382 10.0 The conversion utility for converting CiscoWorks Wireless LAN Solution Engine...
View all Cisco CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2008-4128 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.

Start Free KEV Monitoring →