ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog

highExploit / PoC exploited in the wildimportance 60CVE-2008-4128

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2008-4128
Cross-Site Request Forgery in Cisco IOS 12.4 HTTP Management Interface

Cisco IOS 12.4 contains multiple cross-site request forgery (CWE-352) flaws in the IOS HTTP management web interface that allow a remote attacker to execute arbitrary commands on the device. The flaws are triggered when an attacker induces an already-authenticated privileged (level 15) administrator's browser to send crafted HTTP requests to the router's web server, for example a "show privilege" command via the /level/15/exec/- URI or an "alias exec" configuration command via the /level/15/exec/-/configure/http URI, letting the attacker run commands with the administrator's privileges, potentially including device reconfiguration. Any Cisco IOS 12.4 device with the HTTP/HTTPS management server enabled and reachable from an administrator's browser is affected. CISA added the issue to the Known Exploited Vulnerabilities catalog on 2026-07-13, indicating known exploitation in the wild, and EPSS assigns a 33.9% probability of exploitation in the next 30 days (98th percentile); no public proof-of-concept is known and ransomware use is not confirmed.

Do: Inventory Cisco IOS devices for the 'ip http server' / 'ip http secure-server' configuration, and disable the HTTP/HTTPS management server where it is not needed or restrict it to management networks via access control lists. Apply Cisco's vendor-recommended fixed IOS release for CVE-2008-4128 in line with CISA BOD 26-04 deadlines, prioritizing internet-facing routers. Because exploitation is confirmed, also review device configurations and logs for unauthorized 'alias exec' entries or unexpected configuration changes.

34% KEV
  • Cisco IOS 12.4 (the only version specified in the source data)
largelikely tens of thousands of internet-exposed Cisco IOS devices with the HTTP management server enabled (unknown exact count)
Full article239 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco IOS flaw, tracked as CVE-2008-4128, to its Known Exploited Vulnerabilities (KEV) catalog.

Cisco IOS 12.4 running on Cisco 871 Integrated Services Routers contains multiple CSRF flaws in the HTTP Administration interface. A remote attacker can trick an authenticated administrator into executing arbitrary commands, including privilege-related and configuration commands, potentially compromising the device.

“Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain “show privilege” command to the /level/15/exec/- URI, and (2) a certain “alias exec” command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.” reads the advisory.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerability by the end of this week, on July 13, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/195262/security/u-s-cisa-adds-a-cisco-ios-flaw-to-its-known-exploited-vulnerabilities-catalog.html