I think anything could be "hacked" given enough time and persistence. Most consumer routers are never setup correctly, especially when clients set them up themselves. A visit to
https://shodan.io will dazzle you with the amount of unsecured devices on the internet!
I still get residential and business clients using the default admin/admin login.
They use WEP 'cause it's a pain remembering passwords, so the risk of getting hacked is greater.
I go for a walks around my neighborhood with my mobile looking for unsecured WiFi networks. When I find one, (which is often) I knock on the door and introduce myself. I try to explain to them that they are insecure. Some are shocked and want it setup correctly, some don't give a rats ar*e, 'cause Mum can't connect if we put a password on it, or "Harry" next door is using it as well!
I pick up quite a few extra jobs doing this.