You can implement connection rate limiting in the firewall.
The problem with "researchers" is: you can always think up another "vulnerability" and publish a CVE. Then some people panic and the developers have to start coding again.
And worse: after implementing some measures, the normal every-day use of the device, even in setups where a problem isn't important at all, is impacted.
And all that only for those "researchers" (often at some university) to get research budget...