The SEP is supposed to enforce a time delay between passcode attempts to prevent this sort of brute forcing. The timer could be defeated in older models by cutting power at just the right time, but Apple's whitepaper says it's supposed to survive restarts now.[3]
Based on the screenshots it looks like it can load custom firmware on the iPhone. That's bad.
[1] https://www.anandtech.com/show/12525/security-researchers-pu...
[2] HN discussion: https://news.ycombinator.com/item?id=16597626
[3] p15: https://images.apple.com/business/docs/iOS_Security_Guide.pd...