The line that matters is easy to miss: Ubiquiti says “reachable from the network” means the network path, not a firewall. Whoever can route packets to the box that protects your self-hosted stack can knock it over. It’s only denial of service, but when the gateway falls over, every tunnel, model server and home-lab service behind it goes with it.
What I’d do: check the firmware version before anything else. Ubiquiti doesn’t say which component is vulnerable or what an attack looks like, so there is nothing clever to mitigate. Patching is the whole plan. Some fixes have been out since last month. If you auto-update everything except the router because it felt too important to touch, that’s the one to fix.
The story — Ubiquiti has patched UniFi firewall and gateway vulnerabilities that attackers with network access can abuse for denial of service: out-of-bounds writes, out-of-bounds reads and uncontrolled recursion, six CVEs each rated CVSS 7.5, high. Fixed firmware: 5.1.31 for Dream Machines, Enterprise Firewalls, Dream Routers, Cloud Gateways and Dream Wall; Express 4.0.21; Express 7 5.1.31; UniFi Gateways 5.1.26 and newer. Some updates have been available since last month. (Source)