If this is calling out, even to just their own servers for information about just their own products, even if only when an admin is actively using the UI and we can lock that account down, and there is no way to completely disable it, we will have to replace all the kit we have of theirs and never buy more. As well as offending our idea of security it simply won't pass the security audits we have to perform for our clients.
And for a "to completely disable it", blocking at the firewall level is not sufficient. Anything trying to call out will fail us on such audits.
Holding software/firmware versions back to avoid the feature won't wash either. Unless there is a security related reason to hold back an update beyond a reasonable "not jamming new code into kit the office relies on in case it breaks things" testing/resting period, then holding back on infrastructure updates is itself a security audit fail.
[FYI: getting Ubiquiti kit in the first place was not our call but it has worked well enough - it might be our call to plan its replacement with something else, and if I shall name this activity Project Ubiquiti-quity]