That said, I've more or less completely ignored IoT so far aside from passing interest in how easy Mirai was and I've only briefly dabbled in firewall configuration, so many of my assumptions could be wrong.
That said, I've more or less completely ignored IoT so far aside from passing interest in how easy Mirai was and I've only briefly dabbled in firewall configuration, so many of my assumptions could be wrong.
Separately, no - attacks like CSRF will quite happily be routed and compromise an incompetently designed IoT device.
CSRF has been around since 2001 and is in the OWASP top 10. It would be absolutely valid for regulators to require reasonable steps to be taken to prevent its abuse, along with similar attacks.
This of course doesn't do anything to secure attacks via one of those trusted addresses, but does prevent someone just happening across an open device.
There's also the problem of coping with dynamic addresses, but that can probably be handled separately.
Routers do have a solution: some support setting up a VPN, to which the phone could securely authenticate against. But good luck getting users to configure that.
Or they can be attacked over the LAN before the router gets a look at the traffic.