Executive brief
A security vulnerability exists in the web-based management interface of certain Cisco routers. If an administrative user visits a malicious website while logged into the router's management console, an attacker could silently execute commands on the device. This could allow an unauthorized person to take full control of the network hardware, potentially leading to data interception or network outages.
Technical details
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities exist in the HTTP Administration component of Cisco IOS 12.4. The flaw is rooted in the lack of unique, unpredictable tokens for sensitive administrative requests. An attacker can exploit this by tricking an authenticated administrator into clicking a malicious link or visiting a crafted webpage. Specifically, the vulnerability allows command execution via the '/level/15/exec/-' and '/level/15/exec/-/configure/http' URIs using 'show privilege' and 'alias exec' commands. Successful exploitation grants the attacker the ability to execute arbitrary commands with level 15 (administrative) privileges.
Affected products
- Cisco IOS 12.4
- Cisco 871 Integrated Services Router 12.4
Timeline
- 2008-09-18: disclosed: Initial NVD publication
- 2026-07-13: advisory: CISA-ADP enrichment and update