If they've seized the C&C domain, can't they push an update that disable the malware?
Also, chances are courts would deny them such orders on the grounds that it would be easier for about everyone involved if the FBI just asked the router’s owner to restore its firmware (why would the FBI need a court order against foo because bar hacked its modem?)