Let's not blame the victim. The general consumer does not buy a device assuming it's ripe for hacking and that they have to take extra steps to configure it more securely.
It's the manufacturer's fault to allow the weak configuration in the first place.