CVE-2008-4128 Cisco IOS CSRF Vulnerability Added to CISA KEV — Exploited by Russian FSB Center 16 (Static Tundra / Berserk Bear) in Ongoing Router-Hygiene Espionage Campaign — Threadlinqs Intelligence
As of 2026-07-13, CVE-2008-4128 Cisco IOS CSRF Vulnerability Added to CISA KEV — Exploited by Russian FSB Center 16 (Static Tundra / Berserk Bear) in Ongoing Router-Hygiene Espionage Campaign is a high-severity vulnerability threat attributed to Static Tundra (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-1272 · Severity: HIGH · CVSS: 9.3 · Status: ACTIVE · Category: VULNERABILITY
Attribution: Static Tundra · Russia · ESPIONAGE
CISA added the 2008 Cisco IOS HTTP administration CSRF flaw CVE-2008-4128 to its Known Exploited Vulnerabilities catalog on 2026-07-13 with a 2026-07-16 remediation deadline, citing active
CVE-2008-4128 is a set of cross-site request forgery (CSRF) vulnerabilities in the HTTP administration interface of Cisco IOS 12.4 on the 871 Integrated Services Router. The flaw allows a remote, unauthenticated attacker to trick an already-authenticated administrator's browser into issuing privileged commands — including a 'show privilege' request to the /level/15/exec/- URI and an 'alias exec' command to a related endpoint — resulting in arbitrary command execution at privilege level 15 without the victim's knowledge. Although originally disclosed and rated only CVSS v2 9.3 / CVSS v3.1 4.3 in 2008, CISA added it to the KEV catalog on 2026-07-13 (last-modified date on NVD also updated to 2026-07-13) with a compressed 2026-07-16 remediation deadline under BOD 26-04, confirming ongoing active exploitation against internet-facing legacy Cisco routers seventeen years after disclosure.
The re-emergence of this old vulnerability is directly tied to a joint international cybersecurity advisory (CISA/FBI/NSA plus 13 allied nations, published 2026-07-09, 'Improve Router Hygiene') attributing systematic scanning and exploitation of poorly hardened, end-of-life Cisco network devices to Russia's FSB Center 16, publicly tracked as Static Tundra (Cisco Talos), Berserk Bear / Energetic Bear / Crouching Yeti / Dragonfly / Ghost Blizzard (industry aliases). The advisory describes attackers scanning the internet for routers with default or weak credentials and exploiting known vulnerabilities — including this decade-plus-old Cisco Smart Install / HTTP admin flaw class alongside CVE-2018-0171 — to gain a persistent foothold on network infrastructure across the defense industrial base, communications, energy, financial services, government facilities, and healthcare sectors in 13+ countries. The group has been separately linked by CISA/FBI/NSA to a December 2025 attack on Poland's energy grid.
Static Tundra's broader tradecraft, documented by Cisco Talos and corroborated by the FBI (August 2025 advisory) and independent research, shows a mature campaign: attackers exploit Smart Install (TCP 4786) and web administration interfaces on unpatched/EOL Cisco IOS and IOS XE devices, force victim devices to upload startup/running configuration via TFTP, parse the stolen configs for Type 7 passwords, plaintext credentials and SNMP community strings, then use those credentials to pivot deeper into victim networks, create privilege-15 backdoor accounts, modify ACLs/TACACS+ configuration for defense evasion, and in some cases deploy the SYNful Knock firmware implant (first documented in 2015) for stealthy persistent access via crafted 'magic packets.' Given this pattern, CVE-2008-4128's KEV addition should be read as part of the same legacy-router exploitation toolkit rather than an isolated 2026 disclosure — the attackers deliberately target old, forgotten CVEs on devices organizations have failed to patch or decommission.
Weaknesses (CWE)
CWE-352, CWE-121, CWE-798
Target sectors: defense industrial base, communications, energy, financial services, government administration, health, telecoms, higher education, manufacturing
Target regions: North America, Europe, Asia, Africa, ukraine
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2008-4128, CVE-2018-0171, T1595, T1190, T1059, T1505, T1136, T1547, T1078, T1562, T1601, T1552