@nprofile1q... That's a lot of requirements. First, no one said it could be attacked without a connection to the outside world which is pretty much a safe assumption if it's a routing device of any kind and your not as insane as I am when it comes to security.
I don't think you actually meant that though ... so I'm not entirely sure how to respond to the question.
I also firmly believe that we can't have a serious conversation about security until we have a complete set of source code so ... if your taking taking that as your premise I'm not really sure I can help you.
Right now security is atrocious period and outside of a handful ~ of devices I have zero confidence.
All that said there are certainly other concerns that can be addressed far more easily than low level firmware related issues.
However acting like the security issues don't exist simply because we can't see the code is a fools errand.
There have been lots of security related issues whether or not there are any that I'd classify as particularly dangerous in the scheme of things could be another situation.
However I can point to some of the obvious ones that have protruded in the past decade:
Spectre/Meltdown and variants...
It's worth pointing out that it's not one vulnerability that is often the issue, but vulnerabilities combined that are exploited and become dangerous.