I guess ISP specific attacks (with ISP specific boxes) wouldn't be that much of an issue as the ISP could be blocked. Will deny service to all users there, but the fault is clearly with the ISP, so they have to fix it. It's much more problematic if a generic router that's being used across the globe has a vulnerability. Filtering traffic will be much harder and ISPs will deny responsibility as it's not due to their machines.