The problem is that mom and pop can't possibly be expected to do this. They are trusting that the device they buy or the device their ISP provides, is secure.
It's the HP T5735. It's second hand from ebay. I got the fat version that has an extra PCI slot and I put a Realtek gigabit NIC in there. It's fast enough for home use, it does not saturate with my 200 megabit link. I use a TL-WR1043ND as an access point and VLAN-capable switch.
I switched from OpenWRT to pfsense a while back and I am never going back. It runs great in a virtual machine, if that's your thing and you already have a need for VMs.
HP T5735, there is a wide version of it with a PCI slot. I don't know about prices worldwide but 40$ is pretty much what I payed for a second hand one here in Germany.