If you can dream up a sick way to mess with people, odds are there is a government somewhere funding research into it.
I'd say routers are particularly vulnerable, if only because they are smart (Linux) machines, but in most cases users will never check them for anything odd going on. As this article shows, it takes but a simple command for them to execute stuff, and given how Linux is a general purpose OS, they could install and perform any kind of task - like install backdoors and whatnot on the PC's behind the routers, which can then in turn be disabled or used in a massive botnet to perform a DDoS or other attacks on other systems.
Just think about the implications of there being a backdoor in every internet-connected computer system, or the consequences of all-out cyberwar.
One of my Projects attempts to solve this problem for the new generation of IP-enabled Appliances/Devices. I plan to make the process painless and easy. Everyone wins, both customer/consumer and developers/providers. Does anyone want to build it with me?
[1] http://www.washingtonpost.com/blogs/the-switch/wp/2013/10/14...