Whatever mechanism was used to upload the firmware in the first place could be exposed. Having a doorlock that can be configured online is asking for it. That's the kind of thing that will lead to headlines in regular news publications.
https://www.google.com/search?q=smart+door+lock+vulnerabilit...