Exploited Known exploited (KEV) CVE-2008-4128

Cisco IOS 12.4 cross-site request forgery (CVE-2008-4128) — an eighteen-year-old flaw, with three days to fix

Cisco IOS Added to KEV Jul 13, 2026 Federal remediation due 2026-07-16

A flaw that makes a network device carry out administrative actions by way of a logged-in user's browser. The identifier dates from 2008 while the catalog listing came in 2026, and the allowance for remediation was three days. Age does not lower urgency.

Key facts

  • CVE IDCVE-2008-4128
  • Affected (vendor / product)Cisco IOS
  • CWECWE-352
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-07-16 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • A flaw making a network device carry out administrative actions by way of a logged-in user's browser (CWE-352).
  • The identifier dates from 2008 and the listing from 13 July 2026, an interval of eighteen years, with three days allowed.
  • The median allowance is 21 days whether the interval is zero years or more than ten, so age is not an input to priority.
  • Measures name a directive on prioritizing updates by risk and forensics triage requirements, with responsibility stated for evaluating exposure.
  • Only 6 of the 1,694 records this site holds as of 2026-09-04 (0.4%) carry this classification.

1An identifier from 2008, and three days

The identifier here dates from 2008. The catalog listing came on 13 July 2026, eighteen years later. Yet remediation was due on 16 July 2026, an allowance of three days. As the first article showed, allowances of three days or less cover 6.0% of entries, and 85.1% of those were listed in the same year they were numbered. This entry is the exception to that.

Interval and allowance for this entry18 years and 3 daysNumbered 2008, listed 13 July 2026, due 16 July 2026
Entries with an interval of eighteen years among the 1,694 this site holds as of 2026-09-0450.3% of the total
Entries classified as CWE-352, of those same 1,69460.4% of the total

The median allowance is 21 days for entries with no interval at all and 21 days for entries more than a decade old. The catalog does not relax deadlines because a flaw is old. What sets urgency is not age but whether something is being exploited now.

2Working through the user's own browser

Cross-site request forgery does not have the attacker walk in. It has the browser of someone already logged in send a request they never intended. To the device, the action looks like it came from a legitimate administrator. Both routes given here are URIs for carrying out actions at administrative privilege. Only six entries in the whole catalog carry this classification, which makes it a rare shape.

Rare also implies that defenses against this shape may be less well established than for commoner ones.

3The required action reads differently again

The measures for this entry name a directive on prioritizing security updates by risk, together with forensics triage requirements, and state that stakeholders are responsible for evaluating each asset for internet exposure. As with the first article, it does not stop at applying updates. An eighteen-year-old flaw is being met with measures that include looking and assessing.

4The eight intervals, side by side

These articles have walked out along the interval between an identifier being issued and its entry reaching the catalog, from zero years to eighteen. The denominator is the 1,694 records this site holds as of 2026-09-04.

IntervalIdentifierWhat is affectedAllowance
0 yearsCVE-2026-21962Oracle HTTP Server and the WebLogic proxy plug-in3 days
1 yearCVE-2020-11651SaltStack Salt, configuration distribution181 days
2 yearsCVE-2020-36193PEAR Archive_Tar, a PHP component21 days
3 yearsCVE-2018-11776Apache Struts, a web framework181 days
5 yearsCVE-2020-24363TP-Link TL-WA855RE, a home range extender21 days
7 yearsCVE-2018-4063Sierra Wireless AirLink ALEOS, industrial communications21 days
12 yearsCVE-2010-2568Windows, shortcut parsing21 days
18 yearsCVE-2008-4128Cisco IOS 12.4, the management interface3 days

Of those same 1,694 records, 731 (43.2%) were listed in the year they were numbered, the largest group; 369 (21.8%) show a gap of five years or more, and 96 (5.7%) a gap of ten or more. The median allowance stays at 21 days across every one of those layers.

Together with the fact that the same manufacturer sits at both ends of the table, the list makes one point. For this catalog, the age of a vulnerability is not an input to priority. The only input is whether it is being exploited now.

Why it matters

The age of a vulnerability and whether it must be fixed now are separate axes. The catalog gives old entries the same allowance as new ones and sometimes imposes three days. Old equipment missing from an asset inventory is exactly what cannot meet such a deadline. Deprioritizing by age does not fit how these deadlines are designed.

FAQ

What is cross-site request forgery?
A technique where the attacker does not enter directly but makes the browser of an already logged-in user send an unintended request, which the device sees as legitimate.
Why three days for an eighteen-year-old flaw?
The catalog lists what has been confirmed as exploited. Deadlines read as set by current exploitation rather than by age.
Is the affected product still in use?
The references include material showing the affected release train has been moved to obsolete status. Whether it still runs depends on each organization's asset inventory.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Vulnerabilities#KEV#Security#Network equipment#Older vulnerabilities
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.