CVE-2008-4128

Executive Summary

Multiple CSRF flaws in Cisco IOS 12.4’s HTTP Administration on 871 ISR allow remote attackers to trigger arbitrary command execution via crafted "show privilege" and "alias exec" requests. The vulnerability is actively exploited (CISA KEV), enabling attackers to gain privileged access and compromise router functionality.


Authoritative CVE Metadata - CVSS Base Score: 8.1 (HIGH) - Published: 2008-09-18T20:00:00.530 - Last Modified: 2026-09-24T12:52:19.010

[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2026-07-13)

Original Description: Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

"All truths are easy to understand once they are discovered; the point is to discover them."

— Galileo Galilei
Source: NVD