Earlier quoted context omitted.
There's lots of ways for this expectation to be broken. The most obvious is UPnP, where the device can ask the gateway router to forward ports. The second is the fact that devices on the LAN are accessible to other devices on the LAN. Malicious JS in a webpage can scan for and compromise other local devices. And the third is the fact that whatever serves code to the toothbrush (whether it's firmware updates, or an HT…
> The second is the fact that devices on the LAN are accessible to other devices on the LAN. Malicious JS in a webpage can scan for and compromise other local devices. Which browser API enables that?
https://security.stackexchange.com/questions/177486/can-webs...
As the adage goes, the "S" in IOT stands for "Security".