TP-Link exploit gets conf.bin without authentication.
If any attacker sends Referer Header with its request and sets Referer: http://192.168.0.1/mainFrame.htm its no authentication required and an attacker can do router's action without authentication. below are some of few examples you can see. But the attacker can do mostly all of the action on a router without Authentication.
Vulnerable devices:
*TL-WR840N
*TL-WR841N
*WL-WA850RE