That's a big thread resurrection to essentially read too much into the CPE acronym. I wasn't referring to a managed enterprise service, just that there's not a huge amount of point in trying to make firewalls capable of providing real security to a 500Mbps+ connection cheap enough to give away, when the ISP can provide them from a virtual platform with all the scalability and resiliency benefits of the cloud and the cost savings because they are really unlikely to need to provide the full throughput to every customer at once.
There's no reason for the security element to live in the customers house, unless they specifically want to, in which case give the customer the option. The advantage of turning the Home Hub or whatever into a device a bit like a lightweight AP is that all the config can be handled from the ISPs control panel so you won't need to back it up, someone else can manage it for you etc.