Linux 3.x has a lot of CVEs filed against its Bluetooth implementation.
Does the image have bluetooth stack ? There is no reason to include bluetooth stack into the build.
Yeah, you could potentially MITM them with a rogue cell tower, I suppose.
I'm curious about the researchers still having the device. They could also see all the cloud endpoints that were being accessed. Are they secure?