He is also able to modify this traffic and serve compromised pages.
The attacker needs to have a stronger signal than the legitimate access point. So he has to stand pretty close to the victim, physically.
In practice, as long as you only trust data received through TLS, you should be fine.
Which is the case for the vast majority of wifi users.
It is completely irrelevant how any of us here consider their access point. The problem is that the masses could be subject to these attacks and allows propagating malwares and botnets.
The only situation where trust in the router would be relevant to me is for communication within a local network, so I'm controlling every device involved. And there, this attack might actually be harmful, as far as I understand.