← Back to context

Comment by palmfacehn

5 days ago

Routers with vulnerable URLs. You can search for: "router" "authentication bypass".

Isn't CORS supposed to prevent this?

  • CORS doesn’t prevent requests (i.e. GET requests from IMG tags, or XHR preflight requests), it only prevents web apps from processing the response if the responding server doesn’t agree. And a simple GET or even OPTIONS request can be enough to exploit vulnerabilities in routers and other local devices.