He did have port forwarding enabled, not 5900, but he was hosting services.
So, any number of things could have exposed his network and then the hacker could use anything they wanted. Simple, really, exploit a hole in service X, add your own app or use one installed, get access to other things.
As for Routing, I don't need a lesson, I was talking about his device, which is a ROUTER not a firewall.
I can place any of my firewalls in DROP-IN (non-routed) mode and have the same IP's on all jacks - then the rules determine what passes between jacks - he can't do that on his cheap NAT Router.