Well, nobody brought a WAN-side vulnerability. And if mischievous Alice can execute arbitrary code from the LAN-side, it doesn’t really matter whether Bob Robert disabled UPnP IGD or not. Because he is already doomed.
The only reason I’ve assumed UPnP was involved in the OP’s case was because IPs were external. If his game server was hacked, it could brute-force Truenas SSH from the LAN as well.
There is a very popular software that is exposed to the internet and had critical vulnerability in the past (and even not in the so distant past, as routers running UPnP on WAN port). I’m talking about OpenVPN and (OpenSSL’s) Heartbleed.
And yet I didn’t see any recent article/topic with the statement “Running OpenVPN (or any OpenSSL-related soft) on your server is a really bad idea!”
Hereby I declare the rise of a new cult – “Disable OpenVPN ASAP!!1”. Just so everybody could be consistent.
I’ll simply suggest disabling ANY service that you don’t use / need. I do it for my network equipment, my NAS, etc. I don’t single out UPNP for disablement, it just joins a long list of other services that I kill, tarhole, or otherwise disable.
For example, many IP cameras like to phone home by default and punch holes in the firewall. You can disable this feature for the most part but funnily enough, it has a way of turning back on, but only occasionally. So add some suspenders to the belt, ie put the cameras on a separate VLAN, disable internet access to them at the gateway, black hole their DNS for good measure, etc.
Similarly, allowing WPA1 or WDS on your WiFi network is literally begging for trouble. People make convenience vs. security tradeoffs all the time. UPNP is just another one of those tradeoffs. I don’t have a use case for UPNP here so it’s turned off not because I joined a cult but rather because it’s just part of my policy.