Earlier quoted context omitted.
Again with the ‘works over the LAN’. What do you think that actually means, because I keep explaining that doesn’t mean what you seem to think it does, and then you keep repeating it in a context which doesn’t make any sense.
It means that my device at e.g. 192.168.123.45 can be controlled by my phone or computer at 192.168.123.46 on the same LAN without any of the traffic going over the internet. And since none of the traffic goes over the internet, the device can be completely blocked from internet access without disabling the ability to control it. I'm not really sure what the disconnect is here. This seems like the obvious meaning of…
A LAN (or WiFi) typically has routability to the Internet (though doesn’t have to, of course!) which is why what you are saying is confusing. It has for at least 20 years, and is especially true in residential, but also true even in commercial.
Those some IP addresses could also be NAT’d, and often are.
Most modern products have also spent significant R&D figuring out how to bypass NAT and firewalls and even hide from packet inspection (tunneling DNS and command and control over HTTPS, for one example).
Very few people are able to handle or setup actual air gapped LANs now (or isolated VLANs), but anything besides that is risky in these scenarios.