This strikes me as a naive, if understandable, viewpoint. The average person on the street I'm sure gives special consideration to passwords as a concept, but from a security perspective they're just entropy. Engineers frequently use things like a "sufficiently random string" in a URL as a pseudo-password, or a username only on HTTP basic auth, or API keys that aren't "passwords" but are "keys", all of these are the same concept – unpredictability.
This is obviously a sad outcome for the researcher, and for the German cybersecurity industry, but I'm also surprised that the court was happy with such a shallow interpretation of security, as it theoretically opens the door to types of misuse that don't depend on passwords to be defended, and may prevent legitimate uses that happen by chance to depend on passwords. The boundary seems to have been drawn in a place that won't be useful for anyone.