On Wed, 4 Nov 2015 13:30:17 -0500, Mark Brown wrote:
> Maybe I'm naive,  but I would figure that someone would need a socket
> open to the device (on the internet side) in order to attempt an
> exploit.

That's not necessarily the case. Because a firewall processes packets
it is theoretically possible to exploit one using a sequence of crafted
packets. As an example of the concept look for wireshark exploits.

