I don't own one of them, but I would surely be able to instruct my router to put it in jail like I can every other device.
LAN-only.
LAN-only.
When I'm elsewhere it can continue to not have the passwords to anyone else's wifi.
For those with more expansive threat models, intentional dvice or network spoofing or cloning might bebrisks.
Since firewalling is performd off-device (on the home-LAN router), this will resut in an unsecured evice.
My preference would be for some on-device configured networking limits. Putting full reliance in fixed-site infrastructure migh be unpleasantly surprising.
That's assuming the device doesn't use straight IP addresses for whatever it's communicating with. That's possible, but pretty unlikely.
Again my point is that relying on off-device, local-netork hardware and configs is brittle.