

I’m not clear about your setups at all sites. In the details for case 4 there’s a Firestick (customized Android) connected to WG (WG running on the Firestick?) but in your summary there’s a laptop in case 4 and the Firestick isn’t mentioned.
I suspect at least part of the problem is that Android does not tunnel hotspot client traffic. It provides Internet but not WG connectivity. Only the phone’s apps will be able to connect through the WG tunnel.







What are the tunnel subnets? Are you using a reverse proxy to access local devices, or DNS rewrites?
I’d start by looking for subnet overlap somewhere.