you would still need to have ports forwarded to the NAS from the internet, a compromised router, or the NAS connected directly to the open internet. All of which are a bad idea.
If the device is vulnerable to a CSRF, then couldn't it be compromised simply by some browser on the LAN ending up on an unfortunate site that does some javascript hijinks to POST to likely, internal, IP addresses for a NAS? No open WAN ports needed.
Also, wasn't there a remote root exploit for samba4 patched just days ago?
However, there's really no reason to expose samba shares to the Internet. There are much better and more secure methods. As to the unfortunate victim, there's most likely no way anyone will be able to retrieve what has been locked by the remote attacker - except the remote attacker.