I'm assuming the firmware is cryptographically signed, because they have to upgrade from untrusted devices. That negates this entire attack vector.
But yes I think this is more a "hey there is so much insecure tech out there - here is another example" as opposed to "we are all dead and our bank accounts emptied"