Earlier quoted context omitted.
manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also been changed I don't think that's a reasonable assumption at all -- the router should ensure that the admin cred has been set to a (reasonably secure) password. Just because someone read on a web page that they should enable remote admin doesn't mean that they understand the risk…
How do you know this router doesn't already do that? You're making some wild assumptions here. Even your basic free Comcast router comes with sane defaults, and tons of warnings for every configuration change. Here's the user manual for the TP-Link AC2300 - The Archer C7 found in the google results this post links to: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 forces the default password t…
Sure, and you can change that password to "foobar" or whatever bad password you want. And I bet that login page doesn't have any rate limiting or a lockout after too many failed logins.
Fortunately, though, I don't think there are any of these that enable remote admin by default, so the owner would need to do that explicitly. Hopefully they've paired that with a strong password. Even then, I still wouldn't advise anyone actually doing this...
(Your manual link is broken; it takes me to a page that just links to TP-Links main marketing website.)