Hacker News new | ask | show | jobs
by duskwuff 4127 days ago
That doesn't actually mitigate the problem much, if at all. Many of these devices are likely to be vulnerable to CSRF; a malicious web page may be able to trigger requests which log into a local router and perform management tasks.
1 comments

I think modern browsers prevent cross-requests to local subnets so this may mitigate CSRF