Re: What I'm having trouble understanding...
Most ISP's these days ship out obligatory routers with no admin password (well you might get a junior admin password, but super admin belongs to the ISP). I had to threaten to take my ISP to court to get a Cisco modem substitute for the router. With the modem, I can put my own router behind it (I did that before with the default router but that leads to some issues with obtaining an IP address on external services as often one gets the front router IP and not the external IP).
In any case, unique admin ID's and passwords per issued device are a pretty good start to security. Heads above the primitive but brutal VNPFilter exploit.