Piotr
Have you experienced these "security holes in web interface" personally?
Yes. I did your test (I cleared browser cache and restarted my computer and dns-323). Holes are present. BitTorrent is my favourite example:
http://<dns323ip>/web/bt/fe01.html
http://<dns323ip>/web/bt/fe02.html
http://<dns323ip>/web/bt/btsettings.html
Everybody can download torrents using my NAS, everybody can change its BT settings.
Other interesting things which can be accessed:
http://<dns-323-ip>/etc/passwd
http://<dns-323-ip>/etc/shadow
http://<dns-323-ip>/server.pem
http://<dns-323-ip>/etc/ez-ipupdate.conf