Well Let's Encrypt has a solution, it is DNS authentication, which doesn't require Let's Encrypt to establish a direct connection to the device. But you still need a way to automatically renew the certificate (your DNS must have a supported API) and deploy it automatically. But that's not a Let's Encrypt problem to solve.