1. The real meat of this "pwning" was (it seems) a google search to identify the WEB API endpoint. Then it turns out that sending POST requests to this endpoint can turn the light on/off, change its temperature, and change its brightness.
2. In order to turn a light on/off using the "found" api, it is first necessary to connect to the lamp's network. So if I were doing this on my own linux machine, which cannot as far as I can tell connect to multiple wireless networks at the same time, my script to change the settings on the light would include disconnecting from my true wifi network, connecting to the lamp's network, sending the signal to the lamp, disconnecting from the lamp, and then reconnecting to my own network. Is that right? Is this what the bash scripts and apps mentioned in the post are doing?
3. If I lived in the apartment above the OP's (say), and I were malicious, I could even now also access the lamps' networks and, say, set their values to be whatever I wanted. And there is simply no way of stopping this (S in IoT, after all).