A security researcher, Samy Kamkar, has updated a technique he devised a decade ago to create a browser-based attack that tricks NAT devices and firewalls to provide remote access to hidden internal network services.
Assuming you don’t need it (e.g. for VoIP phones), disable ALG to protect your environment from this attack.

