ISPs can send any firmware to a docsis cablemodem, without the user knowing or accepting.
Imagine the damage that could be done by a malicious actor via the ISPs computers.
Or imagine someone being able to hack the system that does that update even without the ISP.
600K users would be a toy, they could do it to 6 Million.
Doesn't even have to be clever, just brick millions of cablemodems.
North Korea or some other government level entity could manage the resources to figure that out.