TLDR; Anonabox can be rooted with minimal effort (backdoor wide open). The attack vector is an undocumented web interface with a hard coded password ("admin"), an open SSH port that accepts the same credentials, and grants root access.
It is clear that they are lazy and a little out of their depth, but are they malicious?