Cisco IOS 12.4 cross-site request forgery (CVE-2008-4128) — an eighteen-year-old flaw, with three days to fix
A flaw that makes a network device carry out administrative actions by way of a logged-in user's browser. The identifier dates from 2008 while the catalog listing came in 2026, and the allowance for remediation was three days. Age does not lower urgency.
Key facts
- CVE IDCVE-2008-4128
- Affected (vendor / product)Cisco IOS
- CWECWE-352
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2026-07-16 (U.S. federal civilian agencies, BOD 22-01)
Key points
- A flaw making a network device carry out administrative actions by way of a logged-in user's browser (CWE-352).
- The identifier dates from 2008 and the listing from 13 July 2026, an interval of eighteen years, with three days allowed.
- The median allowance is 21 days whether the interval is zero years or more than ten, so age is not an input to priority.
- Measures name a directive on prioritizing updates by risk and forensics triage requirements, with responsibility stated for evaluating exposure.
- Only 6 of the 1,694 records this site holds as of 2026-09-04 (0.4%) carry this classification.
1An identifier from 2008, and three days
The identifier here dates from 2008. The catalog listing came on 13 July 2026, eighteen years later. Yet remediation was due on 16 July 2026, an allowance of three days. As the first article showed, allowances of three days or less cover 6.0% of entries, and 85.1% of those were listed in the same year they were numbered. This entry is the exception to that.
The median allowance is 21 days for entries with no interval at all and 21 days for entries more than a decade old. The catalog does not relax deadlines because a flaw is old. What sets urgency is not age but whether something is being exploited now.
2Working through the user's own browser
Cross-site request forgery does not have the attacker walk in. It has the browser of someone already logged in send a request they never intended. To the device, the action looks like it came from a legitimate administrator. Both routes given here are URIs for carrying out actions at administrative privilege. Only six entries in the whole catalog carry this classification, which makes it a rare shape.
Rare also implies that defenses against this shape may be less well established than for commoner ones.
3The required action reads differently again
The measures for this entry name a directive on prioritizing security updates by risk, together with forensics triage requirements, and state that stakeholders are responsible for evaluating each asset for internet exposure. As with the first article, it does not stop at applying updates. An eighteen-year-old flaw is being met with measures that include looking and assessing.
4The eight intervals, side by side
These articles have walked out along the interval between an identifier being issued and its entry reaching the catalog, from zero years to eighteen. The denominator is the 1,694 records this site holds as of 2026-09-04.
| Interval | Identifier | What is affected | Allowance |
|---|---|---|---|
| 0 years | CVE-2026-21962 | Oracle HTTP Server and the WebLogic proxy plug-in | 3 days |
| 1 year | CVE-2020-11651 | SaltStack Salt, configuration distribution | 181 days |
| 2 years | CVE-2020-36193 | PEAR Archive_Tar, a PHP component | 21 days |
| 3 years | CVE-2018-11776 | Apache Struts, a web framework | 181 days |
| 5 years | CVE-2020-24363 | TP-Link TL-WA855RE, a home range extender | 21 days |
| 7 years | CVE-2018-4063 | Sierra Wireless AirLink ALEOS, industrial communications | 21 days |
| 12 years | CVE-2010-2568 | Windows, shortcut parsing | 21 days |
| 18 years | CVE-2008-4128 | Cisco IOS 12.4, the management interface | 3 days |
Of those same 1,694 records, 731 (43.2%) were listed in the year they were numbered, the largest group; 369 (21.8%) show a gap of five years or more, and 96 (5.7%) a gap of ten or more. The median allowance stays at 21 days across every one of those layers.
Together with the fact that the same manufacturer sits at both ends of the table, the list makes one point. For this catalog, the age of a vulnerability is not an input to priority. The only input is whether it is being exploited now.
Why it matters
The age of a vulnerability and whether it must be fixed now are separate axes. The catalog gives old entries the same allowance as new ones and sometimes imposes three days. Old equipment missing from an asset inventory is exactly what cannot meet such a deadline. Deprioritizing by age does not fit how these deadlines are designed.
FAQ
What is cross-site request forgery?
Why three days for an eighteen-year-old flaw?
Is the affected product still in use?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).