In a lot of cases, this would only be exploitable internally, since many
configurations are set up not to allow access to the unit externally.
But in any case, there are a lot of other ways to DoS these little residential boxes. Running macof (part of the dsniff package) will effectively shut down all traffic on the network. I'm sure arpspoof without forwarding would do the same thing. I'm surprised these things don't support something as basic as SSL for authentication (at least the model I've got doesn't)
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html