3 ms·
Correct me if I'm wrong, but in order to perform this attack you need to be connected to the router's LAN in order to access the admin page, right? So you would
by triangleman 7y ago
Correct me if I'm wrong, but in order to perform this attack you need to be connected to the router's LAN in order to access the admin page, right? So you would need to gain access to the WiFi or attach a computer to the router via Ethernet. This cannot be exploited over the internet, unless perhaps the user enables the admin page via WAN.
- crankylinuxuser 7y agoSadly, wrong. Assuming 192.168.1.1 is your router, you can craft a webpage on the public internet to exploit that IP address, without javascript. With js, it's trivial.. But you have to deal with CORS being set up. Question then becomes - is CORS set up right? If not, pwn3d.