It is capable of monitoring ALL http requests, which is only about <5% of traffic going through an ISP. The more traffic you have, the more devices you need, but one can take care of a LOT of traffic, and I believe it can run as a VM. I'm not sure how it works as a VM exactly, because it also contains a custom Ethernet driver.
The same device directs people to the captive portal (if i'm not mistaken) used for logging into xfinity, or other public wifi from other providers.
Because performance is a high priority, the logging is minimal, but it keeps track of who's been served a message and doesn't collect any PII. The device is capable of serving any content, even causing a request from a third-party. So, it's possible that the content that gets ultimately injected is able to do whatever... anything a malicious advertisement would be capable of doing.
Your message eligibility is highly configurable, and can include metrics such as whether you visit certain sites, and possibly even your physical location.
There's a couple phases. First the network appliance injects so light code, using the Man-On-The-Side 302 redirect method. Once that's done, the injected code is probably going to request additional content after checking if you qualify for a message.