Firewall event need help svchost.exe

I got a alert saying svchost.exe is receiving a connection from the internet to port 49739 from port 1901
is this ok to let through?

it appears to be coming from my modem as when i enter the source ip it asks for a password.
I think it is ok to let this through.

but i am not sure why my modem is trying to send something to svchost.exe?

Anyway if it is safe i would like to see CIS handling these kind of alerts by itself, perhaps some sort of treatsence community thing?

I would like to see comodo handle these kinds of alerts betterl. If not it would be cool if it could provide information about the ports, applications or additional information to making these decisions easier.