Just on BugTraq:-

The router gives you a web page with user name, password, primary and
secondary DNS, default gateway, etc, if you access
http://[routerIP]/app_sta.stm without athentification of any kind.

Router details:
Runtime Code Version 1.05 (Jan 27 2004 14:58:25)
Boot Code Version V1.3d
Hardware Version 01A
ADSL Modem Code Version 13.9.38

The password given is the password that you use to connect to the
internet, not to the router.
--
karb0noxyde
Turning it off when you aren't using it would be the only mitigation technique available at present.