Several models of D-Link routers have a built-in backdoor that grants access to anyone who happens to change their browser's user-agent to a very specific string. Specifically, it grants them complete administrative privileges. I'm not sure if there's a fix yet--there might be--so if you have one of the affected models, you probably ought to upgrade your firmware.
Second, but likely less common (in the US anyway) is the backdoor that affects Chinese-made Tenda routers. It's only possible to exploit this backdoor via wireless or via LAN, so unless you have some very shady neighbors, you're probably safe. Probably.