If your router had only NAT and someone (i.e. your ISP) sends it a package addressed to somewhere inside your internal IP range, it will happily forward it. A firewall would block it.
Okay, I'm running tcpdump on my desktop. Send me some packets to 192.168.1.127 and I'll watch out for them.
Find me a consumer IPv4 router sold in the last ~10 years that does that by default.
Security comparisons should be between proposed new tech vs. existing tech, not vs. hypothetical straw-man tech.
Does your ISP attack you often?