A proper config could easily fix that. Either whitelist certain devices for unrestricted access. Or blacklist devices to have to obey the config parameters. And then parameters for which ports and destinations things should be allowed access to on a per device level...
Which is literally describing a firewall/iptables once you drop the "established" incoming rule and block outgoing.
Basically, "I want a router iptables configurator with notifications"