On appVMs this apparently can't be an issue, because _gateway points to a 10. IP class, in fact, it point to sys-firewall's IP (assuming sys-firewall is the net VM set for that appVM in its settings).
On a vanilla Linux though, it seems that websites could access the router by using the _gateway hostname. Does anyone know if this can be done? It'd be kinda lame if so... and I can only imagine the attacks that could be performed.