It relies on the fact that the router web admin page is unsecured and someone hasn't changed the default password. I'm pretty certain this could also work on linksys:linksys or admin:password default login routers.
So if you don't want to be hacked, change your password.