There is no point in spending lots of time & effort trying to secure half-baked half-open devices that are not under my full control. I will do what I can [or what I'm allowed to do by the usually severely restricted configuration modem panel] but I know the game, there, is already lost. Moreover, the ISP can remotely administer the cable modem and flash anything to it.
A second perimeter that is based on infrastructure I fully configure/control/administer is where I still have a chance.