Cisco IOS 12.4 HTTP admin CSRF on the 871 Integrated Services Router
Multiple CSRF flaws in the HTTP admin component of Cisco IOS 12.4 (on the 871 ISR) allow remote command execution via crafted /level/15/exec/ requests. Added to CISA KEV 2026-07-13.
- Vendor
- Cisco
- Product
- IOS 12.4 mainline (Cisco 871 Integrated Services Router)
- CVSS
- 4.3
- EPSS (exploit probability)
- N/A
- Status
- kev
- Published
CVE-2008-4128 is a set of cross-site request forgery vulnerabilities in the HTTP administration component of Cisco IOS 12.4 as shipped on the 871 Integrated Services Router. A remote attacker who can lure an authenticated administrator’s browser to a malicious page can cause the router to execute arbitrary IOS commands via crafted requests to /level/15/exec/- (using show privilege) or /level/15/exec/-/configure/http (using alias exec). Impact is command execution at privilege level 15 without the attacker needing to authenticate to the router directly.
NVD scores the bug 4.3 (medium) on CVSSv2. It was published 2008-09-18. Cisco IOS 12.4 mainline is end-of-life; there is no patched 12.4 build. The vendor URL CISA links from the KEV entry points at Cisco’s obsolete-releases page for 12.4 mainline.
CISA added CVE-2008-4128 to the Known Exploited Vulnerabilities catalog on 2026-07-13, bringing it under BOD 26-04 remediation timelines for federal civilian agencies.
Mitigation options where an immediate platform upgrade is not possible: disable the HTTP admin server (no ip http server and no ip http secure-server) and manage the device over SSH from a fixed jumpbox, or restrict reachability of the HTTP admin interface to a tightly ACL’d management VLAN so /level/15/exec/ cannot be reached from user segments.
See the article Cisco IOS 12.4 CSRF From 2008 Lands in CISA KEV for the full write-up.
