Back to Blog
CVE-2008-4128, CVE-2018-0171: Cisco Router — Remote Code Execution Risk (June 2024)
vulnerabilities

CVE-2008-4128, CVE-2018-0171: Cisco Router — Remote Code Execution Risk (June 2024)

breachwire TeamJul 19, 20262 min read

CVE-2008-4128, CVE-2018-0171 — Cisco Router

CVE-2008-4128 and CVE-2018-0171 are high-severity vulnerabilities in Cisco routers, both enabling remote code execution. Russian state-sponsored APTs are actively exploiting these flaws in critical infrastructure environments. Immediate patching is required to prevent persistent compromise and data exfiltration.

Attack Vector

Attackers scan for internet-exposed Cisco routers with outdated firmware. They abuse SNMP set-requests to enumerate and extract device configurations, then exploit CVE-2008-4128 (HTTP service buffer overflow) or CVE-2018-0171 (Smart Install remote code execution) to gain code execution. Exfiltration occurs via TFTP or compromised FTP/VPS infrastructure. Indicators include unusual SNMP set-requests and unauthorized TFTP transfers.

Who Is at Risk

All organizations deploying Cisco routers with unpatched firmware are at risk, especially in the communications, defense, energy, financial, government, and healthcare sectors. Confirmed targets include critical infrastructure in multiple countries. Devices with exposed SNMP or Smart Install services are particularly vulnerable.

Patch & Mitigate

  • Patch: Upgrade to Cisco firmware versions addressing CVE-2008-4128 and CVE-2018-0171 immediately. Cisco advisories provide specific fixed releases.
  • Workaround: Disable SNMP and Smart Install if not required. Restrict management interfaces to trusted networks.
  • Detect: Monitor for SNMP set-requests from unusual sources, unauthorized TFTP/FTP activity, and unexpected configuration file access in logs.

MITRE ATT&CK

  • TA0007 — Discovery: Attackers use SNMP set-requests to enumerate device configurations.
  • TA0009 — Collection: Configuration files are exfiltrated via TFTP or compromised servers.
  • TA0011 — Command and Control: Persistent access is maintained through compromised routers and external infrastructure.

Source: https://www.securityweek.com/us-allies-warn-of-russian-cyberattacks-targeting-critical-infrastructure-routers/

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: