logo

CVE-2008-4128: Cisco IOS Cross-Site Request Forgery Vulnerability

ID: 715465d6-ff4e-5d06-ba85-05fe55dd7de0

STIX ID: report--715465d6-ff4e-5d06-ba85-05fe55dd7de0

Feed Name: CosmicBytez Labs

Threat Score
68/100

Date Published: 2026-07-13

Date Updated: 2026-07-15

...
...

**Executive summary:** CVE-2008-4128 is a CSRF vulnerability in Cisco IOS 12.4 that can let an attacker cause an authenticated administrative session to execute arbitrary privileged commands via the /level/15/exec/... HTTP paths; CISA added it to the KEV catalog in July 2026 citing active exploitation. Immediate mitigations recommended are disabling the IOS HTTP server, restricting management access, upgrading/replacing out-of-support IOS 12.4 devices, auditing legacy equipment, and isolating management interfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.