>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.
That answer will change very quickly, if someone marches to a Creative show room, sales event or CES and "patches" all of their devices.
Let's hope Creative patches things before something like this happens.