Officials once again warn defenders that Russian hackers are targeting network devices
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2008-4128 | Cross-Site Request Forgery in Cisco IOS 12.4 HTTP Management Interface Cisco IOS 12.4 contains multiple cross-site request forgery (CWE-352) flaws in the IOS HTTP management web interface that allow a remote attacker to execute arbitrary commands on the device. The flaws are triggered when an attacker induces an already-authenticated privileged (level 15) administrator's browser to send crafted HTTP requests to the router's web server, for example a "show privilege" command via the /level/15/exec/- URI or an "alias exec" configuration command via the /level/15/exec/-/configure/http URI, letting the attacker run commands with the administrator's privileges, potentially including device reconfiguration. Any Cisco IOS 12.4 device with the HTTP/HTTPS management server enabled and reachable from an administrator's browser is affected. CISA added the issue to the Known Exploited Vulnerabilities catalog on 2026-07-13, indicating known exploitation in the wild, and EPSS assigns a 33.9% probability of exploitation in the next 30 days (98th percentile); no public proof-of-concept is known and ransomware use is not confirmed. Do: Inventory Cisco IOS devices for the 'ip http server' / 'ip http secure-server' configuration, and disable the HTTP/HTTPS management server where it is not needed or restrict it to management networks via access control lists. Apply Cisco's vendor-recommended fixed IOS release for CVE-2008-4128 in line with CISA BOD 26-04 deadlines, prioritizing internet-facing routers. Because exploitation is confirmed, also review device configurations and logs for unauthorized 'alias exec' entries or unexpected configuration changes. | — | 34% | KEV |
| largelikely tens of thousands of internet-exposed Cisco IOS devices with the HTTP management server enabled (unknown exact count) | |
| CVE-2018-0171 | Unauthenticated RCE/DoS in Cisco IOS & IOS XE Smart Install CVE-2018-0171 is a critical (CVSS 9.8) buffer-overflow vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE, caused by improper validation of packet data (CWE-20, CWE-787). An unauthenticated, remote attacker can trigger it by simply sending a crafted Smart Install message to TCP port 4786 on an affected device, with no credentials or user interaction required. A successful exploit can cause a device reload, an indefinite loop that triggers a watchdog crash, or arbitrary code execution, giving the attacker full control of the switch or router. Any IOS or IOS XE device running the Smart Install service is affected — a configuration commonly present on Catalyst switches — and devices exposed to the internet on TCP 4786 are at direct risk. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog, and both Russian (Static Tundra, FSB-linked) and Chinese (Salt Typhoon) state-sponsored actors have exploited it to compromise unpatched, often end-of-life, Cisco network devices at hundreds of organizations worldwide. Do: Upgrade IOS/IOS XE to a fixed release per Cisco's advisory (Bug ID CSCvg76186); for end-of-life hardware that cannot be patched, plan replacement given active nation-state targeting of unpatched devices. If Smart Install is not in use, disable it with 'no vstack'; otherwise restrict TCP port 4786 with ACLs to trusted management hosts. Audit internet-facing switches and routers for Smart Install enabled and TCP 4786 exposed, and prioritize those devices for remediation. | 9.8 | 99% | KEV |
| mass≈250,000+ internet-exposed devices with TCP/4786 open, on top of a multi-million-device IOS/IOS XE installed base |
Full article585 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
State-sponsored attackers are targeting critical infrastructure networks in defense, communications, energy, finance, government and health care.
Listen to this article
0:00
Learn more.
Russian state-sponsored hackers are breaking into critical infrastructure around the world by exploiting poorly configured and vulnerable networking devices, authorities from the United States and 12 additional countries said in a joint cybersecurity advisory Monday.
Officials once again urged defenders to take more preventative measures to thwart attacks from the Russian Federal Security Service Center 16, which has been actively targeting critical infrastructure for more than a decade. The hackers are also tracked as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard and Static Tundra.
“This is an ongoing issue that has impacted various U.S. and foreign networks across multiple sectors, including the defense industrial base, communications, energy, financial services, government facilities and health care sectors,” the National Security Agency said in a statement.
The state-sponsored attackers scan the internet for vulnerable routers using default or weak passwords, and have also exploited vulnerabilities in Cisco devices, Cisco’s Smart Install feature and web portals to take over network devices.
Two of the Cisco vulnerabilities exploited by the Russian FSB Center 16 hackers are quite old, including CVE-2008-4128 and CVE-2018-0171.
Officials shared technical details of the threat group’s activities and advised network defenders to disable Cisco Smart Install on all devices, use stronger modes of authentication and passwords, monitor for unusual credentials and logins using local accounts.
The joint advisory comes nearly a year after the FBI issued a similar alert about the same group targeting end-of-life networking devices running Cisco Smart Install.
On Monday, the European Union blamed Russia’s FSB Center 16 for a December 2025 attack on Poland’s energy grid. The United Kingdom, also on Monday, sanctioned 24 individuals and entities allegedly involved in various attacks attributed to Russian intelligence services.
“From directing criminals to targeting businesses, and striking Poland’s energy grid in the depths of winter, the Russian state is sinking to new lows in its attempts to undermine European security,” Yvette Cooper, foreign security of the United Kingdom, said in a statement.
Other countries behind the joint cybersecurity advisory include: Canada, Australia, New Zealand, Czech Republic, Denmark, Estonia, Finland, France, Italy, Poland and Sweden.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/russian-fsb-cisco-joint-cybersecurity-advisory/