You might also like to explore this: https://www.shodan.io/ and if you have some time on your hands this: https://www.kali.org/
NAT Is Not A Firewall
So the general idea that things will be safe from being behind nat is more or less wrong, unless you have 100% control over all possible traffic generated from the inner host(s), at which point you could have had it without firewall more or less. Will your robo-hover never phone home, never look for tuesday patches, java updates, OTA firmwares or talk to some license server or whatever? Then nat is ok, but if any of this can happen in some situation, then it is "on the internet" even if it started out behind nat.
It moves a machine along the scale from unreachable closer to unprotected-and-exposed-to-everything even if it's not all the way there.
The big issue for consumer routers is, admittedly, the shoddy quality of the firmware and the fact that even on the occasion where vulnerabilities are fixed, those releases often do not get installed.