Is it possible to set up dropbear such way, that it accepts both login/password and key authentications for local connections, but only key authentication for WAN connections?
Not sure how to do it in the WebGUI, but one can run multiple instances of dropbear, each with it's own config... just make sure to run the instances on different ports.
Could go either way - I'll defer to others that know the ASUSWrt-RMerlin builds better than I do - but if you go behind the WebGUI, things could go weird if you forget what you've done in the past...