They could be bridging this client back to one of the clients other locations and then connecting it to uverse. Quite legit and no different then a PTP link between two of the clients locations. If they knew what they were doing, they would tag it on a VLAN so you couldn't see the other devices across their network. How did you determine that the 20 devices you were seeing were routing traffic out over the uverse connection?