Edit: Note that the example does try to do some DNS rebinding on the router, but that's the end goal. The attack itself doesn't rely on rebinding. It does require "already logged on to the router" users, but I suspect an attack using default login credentials is possible as well.
Edit: Note that the example does try to do some DNS rebinding on the router, but that's the end goal. The attack itself doesn't rely on rebinding. It does require "already logged on to the router" users, but I suspect an attack using default login credentials is possible as well.