DIRAS TAKE
Urgent: CISA added CVE-2008-4128 to the Known Exploited Vulnerabilities catalog with a July 16, 2026 remediation deadline, so prioritize mitigation for internet-facing IOS management interfaces immediately.
What is CVE-2008-4128?
An attacker can cause an administrator’s web-based management session on affected Cisco IOS devices to execute arbitrary commands, CVE-2008-4128. Reports describe CSRF weaknesses in the HTTP administration interface of Cisco IOS 12.4 as used on the 871 Integrated Services Router that allow crafted requests to trigger privileged command execution. Exploitation requires network access to the device’s HTTP management port and that an authenticated admin visits a malicious page; the attacker does not need prior credentials on the device. The weakness is classified as CWE-352 (Cross-Site Request Forgery).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Which versions of Cisco IOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2008-4128 being exploited?
CISA added CVE-2008-4128 to the Known Exploited Vulnerabilities catalog on 2026-07-13, and U.S. federal agencies must address it by 2026-07-16.
How to fix CVE-2008-4128
- Follow Cisco's vendor guidance and apply any published mitigations immediately.
- Block or restrict access to the IOS HTTP administration interface from untrusted networks and the internet.
- Monitor device management logs and for signs of abnormal command execution, and review recent configuration changes.
- If administrative HTTP access is not required, disable the HTTP administration service or move management to a secure management plane.
Frequently asked questions
Is CVE-2008-4128 being actively exploited?
CISA added CVE-2008-4128 to its Known Exploited Vulnerabilities catalog on 2026-07-13; federal agencies must remediate by 2026-07-16.
Which IOS versions are affected by CVE-2008-4128?
Third-party reporting identifies the issue in Cisco IOS 12.4 on the 871 Integrated Services Router; no additional affected versions are listed in the provided facts.
Is there a patch for CVE-2008-4128?
No patch is listed in the provided facts as of 2026-09-29; follow Cisco's guidance and apply recommended mitigations.
Does CVE-2008-4128 require authentication?
The vulnerability does not require attacker credentials but does require that an authenticated administrator be tricked into performing an action (CSRF via the device's web interface).
References
- nvd.nist.gov/vuln/detail/CVE-2008-4128
- cve.org/CVERecord?id=CVE-2008-4128
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2008-4128
- exploit-db.com/exploits/6476
- exchange.xforce.ibmcloud.com/vulnerabilities/45226
- jbrownsec.blogspot.com/2008/09/cisco-0day-released.html
- exploit-db.com/exploits/6477
- securityfocus.com/bid/31218
- All Cisco CVEs on CVE Radar
- CVEs published in September 2026