One a serious note, this exploit is not as bad as it sounds - it tricks the router into exposing the administration page because the router thinks the requester is on the internal network, when in fact they are external. From there, they still need to guess the password to the admin page.
Which is easier, of course, when your “secure” 19 character long password, is in play at multiple sites.
__________________
-Scott
|