Even though soho/commodity routers often see no firmware updates, the biggest problem continues to be simply a configuration issue.
If you leave devices with default settings (e.g. default passwords, telnet administration enabled, etc.) then hackers barely have to work to own your network. Even automated attacks will do the job.
Russia Steps Up Hacking, Spurring U.S.-U.K. Warning on Risk