I think this is more the fault of manufacturers than end users. Routers should be secure by default, and it should be hard to do something that will make it insecure. The router manufacturers are the supposed experts when it comes to networking, expecting every consumer to even know the risks of exposing their router admin interface to the world is not a reasonable assumption.
They should limit vehicle speed to 5mph so I don't hurt myself or others.
I have used many of these routers. Admin access on the wan port is blocked by default and must be enabled by the user.