I think you can do this by serving the user a hidden form that e.g. sends a firmware to the device, and a real form that they are likely to submit. The hidden form is the one that actually gets submitted. But I thought anything via XHR wouldn't work. Which is needed for a brute force attack say.
What did you find?
In which case, I woner why more sites (or evil ads via an ad network) don't attack our home routers?
My first router could only do the 192.168 range so I got in the habit of it. Later with subsequent routers, all my devices were already set up on a specific class C network, so it was easier to change the router than go through all the devices and change them.
Note that the article mentions Intel routers (x86 cpus?). Those are indeed not very common to my knowledge.