There are much better ways of device enrollment; at a minimum they could require device activation that doesn't blindly use a token with no further checks.
I'm concerned about publicly accessible devices containing secrets also. These are not physically secure places to store keys, they are mounted on street lights where anyone with a ladder can get the key material out of the device.
I'm concerned about publicly accessible devices containing secrets also. These are not physically secure places to store keys, they are mounted on street lights where anyone with a ladder can get the key material out of the device.
It's like they have no threat model in place.