Stupid security question:
If someone finds a remote OS command injection in router (which doesn't provide telnet nor ssh) but it's only possible when the user is authenticated is it still considered security vulnerability?
After all user already has to be admin of the device in order to execute something on it

