This is almost certainly exploitable remotely with a DNS rebinding attack.
This issue is based on WebSockets where the software on the modem:
a) Doesn't verify any of the origin headers sent, so any origin works (rebinding is designed to beat origin checks)
b) Copies an uploaded message straight onto the stack without doing any size checks
Edit: or you could get them to click on a link