I'll do some speculation just to see how close I am...
Many of you may have noticed when you try to access your own public IP you get the router web page. Still true? My speculation is that this rule is made advantage of. It's not your LAN IP it's a public IP (that happens to be your own) so it'll get by a lot of security fixes against local addressing. Cross-Site Scripting (XSS) had exploits to access local LAN addresses but this Linksys quirk is sort of an invitation.
IF that's all it is... securing your password off default would be #1. But everyone here should already know THAT, anyway.