I can confirm the Linksys wap 11 v2.2 has the same vuln.

You can get anything from the machine with tftp a friend of mine did it a couple of weeks back.
the password is in plain text format.

The D-Link and the Linksys only differ in box and firmware, the hardware is the same. You can even flash a linksys with the D-link firmware if they fix this faster then Linksys does.

The only trouble is, I have heard that the tftp stuff is in the machine's kernel not in the firmware, so perhaps there is no real cure but to block access to that particular port (tftp uses wich port??)