The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but not encrypted, exposing user credentials to passive interception by attackers on the same network.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.