Well then let me put it in clearer terms for you then since you are unable to understand or explain it or even suggest a solution

Anyone still mining here is at risk and there is no way to mitigate it with the current setup.
Disabling client.redirect doesn't solve the initial connect redirect issue (since that's not stratum)
So if it really is as bad as a MITM then you are screwed anyway until you can stop the MITM or move your pool somewhere else.
It's a lot easier to insert a single TCP packet (containing a client.redirect command) in one direction than it is to intercept an entire TCP connection in both directions.
Whether or not you want to call that a MITM attack is another matter.
It's the reply when you first connect ...