CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2008-4128

criticalknown exploitedpublic exploitcovered by 3 sourcesfirst seen 2026-07-13
Actively exploited. CVE-2008-4128 is listed in the CISA Known Exploited Vulnerabilities catalog (added 2026-07-13) — exploitation has been observed in the wild, and US federal agencies are required to remediate it under BOD 22-01. Treat patching as urgent.
Public exploit code is available. Proof-of-concept or working exploit code for CVE-2008-4128 is indexed in Exploit-DB. Expect opportunistic scanning and exploitation attempts — prioritize remediation.
Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Executive summary Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure Public Service Announcement of the decade-plus FSB Center 16 cyber activity by providing additional tactics, techniques, and procedures (TTPs) to enable defenders to more fully understand and counter the threat. [ 1 ] This CSA is being released by the following authoring and co-sealing agencies: United States National Security Agency (NSA) United States Cybersecurity and Infrastructure Security Agency (CISA) United States Federal Bureau of Investigation (FBI) United States Department of Defense Cyber Crime Center (DC3) Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre) New Zealand National Cyber Security Centre (NCSC-NZ) United Kingdom National Cyber Security Centre (NCSC-UK) Czech Republic National Cyber and Information Security Agency (NÚKIB) 1 Danish Defence Intelligence Service (DDIS) 2 Estonian Foreign Intelligence Service (EFIS) 3 Estonian Information System Authority (RIA) 4 Finnish Defence Intelligence (FDI) 5 Finnish Security and Intelligence Service (SUPO) 6 French National Cybersecurity Agency (ANSSI) 7 Italian External Intelligence and Security Agency (AISE) 8 Italian Internal Intelligence and Security Agency (AISI) 9 The Military Counterintelligence Service of Poland (SKW) 10 Sweden National Cyber Security Centre (NCSC-SE) 11 The authoring and co-sealing agencies strongly urge device owners and network defenders to take mitigation and

CSIRTS triage

vendor: nullproduct: nullOtheraffected: null
What
Russian state-sponsored actors are exploiting poorly configured and vulnerable networking devices.
Who is affected
Critical infrastructure sectors with vulnerable networking devices are affected.
Urgency
Remediation is urgent due to ongoing exploitation and critical severity.
Action
Improve router configurations and security hygiene.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2008-4128

Get an email if CVE-2008-4128 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Exploit availability

Public exploit or proof-of-concept code for CVE-2008-4128 is indexed in these free datasets. Available exploit code raises real-world risk independent of the CVSS score.

Advisory coverage (3)

External references

NVD record for CVE-2008-4128

CVE.org record

CISA KEV catalog

Embed the live status

CVE-2008-4128 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2008-4128 status](https://www.csirts.com/badge/CVE-2008-4128)](https://www.csirts.com/cve/CVE-2008-4128)