Man-in-the-middle
An on-path attacker sits between two parties who both believe they are talking directly to each other.
They can read what passes, and more importantly they can change it. The reason this is not constantly happening is encryption combined with identity checking: your browser verifies it is genuinely talking to the site it thinks it is, not merely that the conversation is private. Encryption alone would give you a confidential conversation with whoever is in the middle, which is why the certificate check matters as much as the padlock.
Checked against the primary source.
