Tailscale. Create an account, put the client on the LAN device, put the client on the remote device, log in on both, you're done. It bypasses NAT, CGNAT, and the firewall through some UDP black magic fuckery. As long as the router allows outgoing connections, it will work.
If the factory resets cause the router to lose connection to the ISP, though, then nothing will work.