vulnti.work

Cisco IOS Cross-Site Request Forgery Vulnerability

中危 CVSS 4.3 CISA KEV 在册
CVECVE-2008-4128
首次发现2026-07-13 00:00 UTC
披露时间2008-09-18 20:00 UTC
最后更新2026-07-14 19:16 UTC
通道状态draft

摘要

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.

中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。

深度研判 · 自动通道

该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。

受影响产品

  • Cisco:IOS
  • :
Lint 边界警告 (4)

以下是本次研判 lint 阶段发现的非阻塞性警告(如引用 URL 未在白名单内)。这些不影响漏洞条目可用性,仅为透明度披露(参 DR-002)。

  • REF_URL_NOT_ALLOWLISTED url not in allowlist: http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.html
  • REF_URL_NOT_ALLOWLISTED url not in allowlist: http://www.securityfocus.com/bid/31218
  • REF_URL_NOT_ALLOWLISTED url not in allowlist: https://exchange.xforce.ibmcloud.com/vulnerabilities/45226
  • REF_URL_NOT_ALLOWLISTED url not in allowlist: https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF

数据来源

  • CISA KEV DATABASE
  • NVD DATABASE

原始链接

时间线

  1. kev_added CISA KEV
  2. nvd_ingest NVD
  3. kev_ingest CISA KEV