The affected product is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.
The affected product is susceptible to cleartext transmission of sensitive information, which could allow an attacker to connect to the broker and read all data.