The zero day were notified by Computer Emergency Response Team(CERT).
A LAN-based attacker can bypass authentication to take complete control of vulnerable devices.
Unfortunately, there are no easy mitigations for the DNS spoofing or firmware over HTTP issues.
source: www.techworm.net