mediumOther

CISA KEV Catalog Addition: Cisco IOS CSRF Vulnerability (CVE-2008-4128)

First seen Jul 14, 2026 · Updated Jul 14, 2026

CISAKEVCiscoCSRFvulnerability-managementfederal-agenciesnetwork-infrastructure

CISA added CVE-2008-4128, a Cross-Site Request Forgery vulnerability in Cisco IOS, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Federal Civilian Executive Branch agencies must remediate this per BOD 26-04, and CISA recommends all organizations prioritize patching this vulnerability on publicly exposed assets.

Technical Analysis

CVE-2008-4128 is a Cross-Site Request Forgery vulnerability affecting Cisco IOS, allowing attackers to trick authenticated administrators into executing unauthorized commands on affected devices, potentially leading to configuration changes or full device compromise. This is a long-known, decade-old vulnerability now confirmed under active exploitation, underscoring that unpatched legacy network infrastructure remains a persistent attack vector. Exploitation typically involves social engineering combined with lack of anti-CSRF tokens in the device's web management interface, granting attackers the ability to alter routing, firewall, or access control configurations. Organizations running AI agent infrastructure that relies on Cisco IOS-based network devices for connectivity to LLM APIs, RAG data sources, or agent orchestration backends could face traffic interception, routing manipulation, or credential/API key exposure if these devices are compromised, making this agent-relevant for any deployment dependent on affected network gear.

Affected Systems

Cisco IOS devices with vulnerable web management/HTTP interfaces exposed to CSRF attacks (specific IOS versions per Cisco advisory for CVE-2008-4128)

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) provided in source advisory

Remediation Steps

  1. 1

    Patch Cisco IOS

    Apply Cisco's official patches or firmware updates addressing CVE-2008-4128 as referenced in Cisco's security advisory.

  2. 2

    Disable unnecessary web management interfaces

    Restrict or disable HTTP/HTTPS management interfaces on Cisco IOS devices, or limit access to trusted management networks only.

  3. 3

    Implement anti-CSRF controls

    Where patching is not immediately possible, use compensating controls such as VPN-only management access and session token validation.

  4. 4

    Follow BOD 26-04 guidance

    FCEB agencies should prioritize remediation of this KEV entry on publicly exposed assets and verify no prior compromise occurred before patching.

  5. 5

    Audit network device exposure

    Identify and inventory all Cisco IOS devices, especially those supporting critical infrastructure such as AI agent or RAG pipeline connectivity, and assess exposure to CSRF attack vectors.

CVE / Advisory IDs

CVE-2008-4128

Industries Most Exposed

GovernmentFederal AgenciesTelecommunicationsCritical InfrastructureTechnology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.