CVE detail
CVE-2008-4128
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 26.4 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
13 source links · newest first
- US and allied Governments’ Recommendations: Securing Network Devices Against Russian APT GroupsSecurity Affairs
eb portals to manage network devices.” Russia-linked threat actors have also exploited known vulnerabilities, including CVE-2018-0171 and CVE-2008-4128 , to compromise network devices. Their techniques overlap with other threat groups, such as Salt Typhoon . Network defenders should strengthen router security by disabling Cisco Smart Install, replacin
newssecurityaffairs.comJul 15, 2026, 6:59 PM (CVEs) in Cisco devices, as well as in the Cisco’s Smart Install (SMI) tool. Actors have exploited, at the very least, CVE-2018-0171 (published in 2018) and CVE-2008-4128 (published in 2008), according to the bulletin. Both of these targeted Cisco routers , giving remote, unauthenticated attackers the ability to execute arbitrary code, take unauthori
newswww.csoonline.comJul 14, 2026, 1:49 AMrabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco IOS flaw, tracked as CVE-2008-4128, to its Known Exploited Vulnerabilities (KEV) catalog. Cisco IOS 12.4 running on Cisco 871 Integrated Services Routers contains multiple CSRF flaws in […]
newssecurityaffairs.comJul 13, 2026, 6:05 PMnetwork devices. The actors previously exploited at least the following CVEs [ T1584.008 , T1588.005 , T1190 , T1068 ]: CVE-2018-0171 CVE-2008-4128 13 Many of these TTPs overlap with activity by other malicious cyber actors, such as Salt Typhoon . Even though this CSA focuses on Russian FSB Center 16 cyber activity, the mitigations below should detect
governmentwww.cisa.govJul 13, 2026, 12:00 PMone new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2008-4128 Cisco IOS Cross-Site Request Forgery Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (
governmentwww.cisa.govJul 13, 2026, 12:00 PMNo excerpt available.
Mitigationwww.cisa.govSep 18, 2008, 8:00 PM- https://www.cisco.com/c/en/us/obsolete/ios-nx-os-software/cisco-ios-software-releases-12-4-mainline.htmlwww.cisco.com
No excerpt available.
referencewww.cisco.comSep 18, 2008, 8:00 PM - https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDFmedia.defense.gov
No excerpt available.
referencemedia.defense.govSep 18, 2008, 8:00 PM - https://www.exploit-db.com/exploits/6477www.exploit-db.com
No excerpt available.
Exploitwww.exploit-db.comSep 18, 2008, 8:00 PM - https://www.exploit-db.com/exploits/6476www.exploit-db.com
No excerpt available.
Exploitwww.exploit-db.comSep 18, 2008, 8:00 PM - https://exchange.xforce.ibmcloud.com/vulnerabilities/45226exchange.xforce.ibmcloud.com
No excerpt available.
Vendor Advisoryexchange.xforce.ibmcloud.comSep 18, 2008, 8:00 PM - http://www.securityfocus.com/bid/31218www.securityfocus.com
No excerpt available.
Exploitwww.securityfocus.comSep 18, 2008, 8:00 PM - http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.htmljbrownsec.blogspot.com
No excerpt available.
Broken Linkjbrownsec.blogspot.comSep 18, 2008, 8:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-20414CVSS 6.5 · Medium
A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF…
- CVE-2019-16009CVSS 8.8 · High
A vulnerability in the web UI of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an af…
- CVE-2018-0255CVSS 8.8 · High
A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (…
- CVE-2009-0471CVSS 6.8 · Medium
Cross-site request forgery (CSRF) vulnerability in the HTTP server in Cisco IOS 12.4(23) allows remote attackers to execute arbitrary commands, as demonstrated by executing the ho…
- CVE-2026-72849CVSS 8.7 · High
Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's…
- CVE-2026-72658CVSS 7.3 · High
Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can sav…