I was thinking about blocking all traffic routed for the IoT device which comes from any address outside a set of explicitly trusted sources (such as the vendor's service and the user's smartphone or something). Then attacks like CSRF and default admin credentials become a moot point unless those trusted sources become compromised.