Cisco IOS Cross-Site Request Forgery Vulnerability
- Severity
- High8.1CVSS 3.1, High
- EPSS
- 34%
- Published
- 18 Sept 2008
- Updated
- 24 Sept 2026
Description
Title, description and vendor guidance are quoted from the source records.
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.
Weakness: CWE-352
Known exploited
Added to CISA KEV on 13 Jul 2026
Federal remediation due date: 16 Jul 2026
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Exploit prediction
34% probability of exploitation in the next 30 days (percentile 98%).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected products
Patcharo shows this vulnerability for information but does not match versions for this product yet.
- n/a n/a · n/a
References
- 6476(opens in a new tab)
- cisco-router-csrf(45226)(opens in a new tab)
- 6477(opens in a new tab)
- https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF(opens in a new tab)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2008-4128(opens in a new tab)
Provenance
Every fact on this page comes from the sources below. Nothing is written by an AI.
- CVE Program record
- CVE Program record · 27 Sept 2026, 23:46 UTC · Parser patcharo-cve5/1.1.0
- CISA Known Exploited Vulnerabilities
- CISA Known Exploited Vulnerabilities · 27 Sept 2026, 23:42 UTC · Parser patcharo-kev/1.0.0
- NVD
- NVD · 27 Sept 2026, 23:44 UTC · Parser patcharo-nvd/1.0.0
- FIRST EPSS
- FIRST EPSS · 27 Sept 2026, 23:46 UTC · Parser patcharo-epss/1.0.0
Last verified: 28 Sept 2026, 02:31 UTC