Hacker News new | ask | show | jobs
by supernetworks 94 days ago
Another favorite, https://www.synacktiv.com/publications/cool-vulns-dont-live-...

the router sniffed plaintext http to grab HTTP User agents to put them into a curl bash command line string. Nice RCE from the browser.