If I can request an SSL cert for a private IP address, how does the CA verify it? Even if they do verify it, what prevents me from using it for malicious purposes on other networks (MITM https://192.168.0.1 with a valid cert or similar)?
For enterprises you can run your own CA, push out the trusted root with Group Policy (or equivalent), so it's not a issue there.
IoT vendors should definitely use HTTPS, but document how to generate a self-signed cert (or generate a request) from their own proprietary interface and how to install it. This would fix the problem.