Linksys E-series Unauthenticated Remote Code Execution Exploit
exploit-db.com
exploit-db.com
For example, I have an Linksys E2000. The "recommended" build on the DD-WRT wiki page is 14929, which is from approximately August 2010. The most recent compatible build I can find is 18946, which is dated 4/7/2012.
Running firmware that is 2 - 4 years old just seems very unsafe.
Which by the way is a pretty solid router so far. Aside from dd-wrt not supporting its 5ghz radio. I tried a Tomato build for it that support 5ghz, but for some reason my router would just lock up every other day with that firmware no matter how it was installed.
I have one of those with DD-WRT as well. A vuln in a router will only affect DD-WRT as well if it's a hardware vuln that allows (for example) corrupting/modifying memory, which would also make the attack need to be highly targeted, or a critical 0day in the linux kernel/dropbear, etc.
I hope my good old WRT54G with tomato firmware is still safe after all these years.
You could then tie it into something like Shodan...
However, you'd be 99% successful trying the most common IPs first:
192.168.0.1
192.168.1.1
10.0.0.1
10.0.1.1
etc.
Then the attacker just sets up a scripted DNS server under their domain, like this: 192.168.0.1.ip.example.com A 192.168.0.1
192.168.1.1.ip.example.com A 192.168.1.1
10.0.0.1.ip.example.com A 10.0.0.1
10.0.1.1.ip.example.com A 10.0.1.1
etc.
As you can see, Same Origin Policy wouldn't prevent javascript from sending a POST request to a subdomain, and the attacker controls their DNS so getting an IP address isn't hard. (The DNS server uses a script instead of actually having all the IP addresses spelled out in a config file.)