Thanks, I must admit when I did the research on this one I didn't read absolutely everything to see if it was new, but I couldn't find any record of these admin logins being known.
There're other outstanding security problems with this particular model and many users will have a worse similar exposure from leaving the completely daft default userid/password unchanged. So with the rep of these things I thought it would be worth blogging what happens when you contact the manufacturer's designated service agent (the ISP in this case) telling them which lines in the GPL source bundle need deleting. So far as per their reputation would be the summary. Of course no sensibile person trusts the zone their telco CPE is in in the first place. Accordingly I already had a replacement, which with there being no libre ADSL2+ is the only ADSL2+ device compatible with blobby WRT distros. The first of which has proven unreliable in use as its a very long running beta (but that's very different from insecure).
