This is why your firewall should be one of the most hardened devices on your network: https://arstechnica.com/information-technology/2018/09/unpatched-routers-being-used-to-build-vast-proxy-army-spy-on-networks/
This is why I run #OPNsense, which includes some of the exploit mitigations and system hardening techniques from #HardenedBSD.