I had a solar inverter mfgr destroy ~$20k in batteries through a unannounced irregular remote update (that was defective) after I inadvertently left open the firewall rule that lets their monitoring platform talk to the inverter after temporarily using it. Had I known there was an update I could and likely would have caught the issue before it had a chance to over discharge the batteries, so the unauthorized remote upgrade was a causative factor-- and not just the fact that the upgrade was defective.
My cable modem, which I own, is installed in a difficult to access location due to my lack of desire to run coax between buildings. In the summer every couple months it has to be rebooted when it loses lock and can't regain it on its own. I used to have a cronjob that would automatically handle it, until comcast without my authorization reached inside my property and applied a change to completely remove the ability to remotely reboot it. The remote reboot stuff was XSS vulnerable, so customers whos client PCs could access the cable modem could have had websites randomly rebooting it on them. This wasn't a problem for me, and could have been fixed by eliminating the XSS vulnerability instead.
Screw giving remote access to third parties.
So I think I'm pretty much 2 for 2 in terms of devices allowed remote access ending up screwing me over because of it. I can only imagine how many additional problems I would have had if I wasn't diligent in preventing any kind of remote access and avoiding having internet connected devices in the first place.