https://nvd.nist.gov/vuln/detail/CVE-2023-1389
the router sniffed plaintext http to grab HTTP User agents to put them into a curl bash command line string. Nice RCE from the browser.