Hacker News new | ask | show | jobs
by js4all 5782 days ago
Yes, when the attacker has control of the router, the user is a helpless victim. The next step will probably be a man in the middle attack for online banking.

Maybe, even if the user changed the default password, he probably stored the new credentials in the browser.