But to be clear, for this to be pulled off remotely, the router must first either disable its firewall or a DNS rebind attack or some other vulnerability must be possible. In the case of a rebind, a victim must also first visit an attacker's server. What would be even more concerning is if any of the routers hard coded with these login credentials are also vulnerable to a rebind or something else by default. Many manufacturers patched the rebind vulnerability back in 2010.