2WIRE gateways have an authentication bypass vulnerability in page=CD35_SETUP_01 that allows you to set a new password even if the password was previously set.
Credit:
The information has been provided by h k m.
Disclosure Timeline:
03/27/2009 - 2wire Contacted no satisfactory response
07/11/2009 - Sent complete details to 2wire no response
07/17/2009 - Sent advisory with video demo to 2wire ticket status escalated, but no response
08/02/2009 - Made public @ Defcon 17