I suspect, that security issues brought up in this article might be already discussed here, but one other question remains - is it true, that password length is really limited to only 16 characters (and does this also apply to Merlin firmware)?
Time to Harden Your Hardware? - Krebs on Security
Time to Harden Your Hardware? - Krebs on Security