The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as passwords and router settings via a direct HTTP request to app_sta.stm.
https://exchange.xforce.ibmcloud.com/vulnerabilities/17723
http://www.securityfocus.com/bid/11408
http://www.securityfocus.com/archive/1/378551