It's still possible to trick the browser of a user on the inside to HTTP POST a form invisibly to 192.168.1.1, by javascript hosted on an external web page.
I think you can do this by serving the user a hidden form that e.g. sends a firmware to the device, and a real form that they are likely to submit. The hidden form is the one that actually gets submitted. But I thought anything via XHR wouldn't work. Which is needed for a brute force attack say.
What did you find?
In which case, I woner why more sites (or evil ads via an ad network) don't attack our home routers?
My first router could only do the 192.168 range so I got in the habit of it. Later with subsequent routers, all my devices were already set up on a specific class C network, so it was easier to change the router than go through all the devices and change them.