Context-Inappropriate Capability
High
- Confidence
- 98% confidence
- Finding
- The guide implements firmware flashing at `/ota` with no authentication or authorization checks, allowing anyone with network access to replace device firmware. This is especially dangerous because the document positions the feature as a 'safe OTA maintenance mode' while also showing weak AP credentials, which lowers the barrier to unauthorized reflashing and device compromise.
