Remote attack surface of router in bridge mode

Does anyone know, if there is any remote attack surface at all, or small enough to be neglected, of a eurodocsis 3 type cable router put into bridge mode?

Background: I need a cheap eurodocsis 3 cable modem to be used in front of an OpenWrt router. Since cable modems are not very common and relatively expensive, I was thinking about using a Fritzbox router in bridge mode to be used as the modem, which does not get OS/firmware updates anymore. I usually don’t use any devices which don’t get updates anymore, but I wonder if there is any remote attack surface in bridge mode at all or if it can be relatively safely neglected.

Bridge mode removes most of the normal router-side exposure, but I would not treat an unpatched cable router as having no attack surface. The DOCSIS/modem side is still managed by the ISP network, and some boxes leave a management UI or services reachable on a local management IP even while bridged. If you use it, I’d at least disable Wi-Fi/telephony/remote admin/UPnP on the Fritzbox, check whether its web UI is reachable from the OpenWrt side, and keep the OpenWrt router doing all firewalling. For a low-risk home setup it may be acceptable as a stopgap, but if you are trying to avoid unmaintained firmware entirely, a supported modem from the ISP is the cleaner option.