Набрёл тут на исследование безопасности маршрутизаторов смотрящих в интернет. Для !Ъ https://community.rapid7.com/community/infosec/blog/2013/01/29/security-flaws...
Для Ъ коротко: Множество моделей разных производителей уязвимы и могут быть скомпрометированы всего одним UPD пакетом.
Somewhere between 40 and 50 million IPs are vulnerable to at least one of three attacks outlined in this paper. The two most commonly used UPnP software libraries both contained remotely exploitable vulnerabilities. In the case of the Portable UPnP SDK, over 23 million IPs are vulnerable to remote code execution through a single UDP packet. All told, we were able to identify over 6,900 product versions that were vulnerable through UPnP. This list encompasses over 1,500 vendors and only took into account devices that exposed the UPnP SOAP service to the internet, a serious vulnerability in of itself.