A network connected device that can be hacked is a small step away from being the first foothold into its server. The fact that on-device security is this atrocious suggests that their server is not any better quality, which means hacking it would probably not take much effort.
I don't disagree.
But there is some old rule about, even the best security can fail if the device is physically accessible.
A Silcon Valley startup with poor server-side security? Couldn't be!