It looks like Arylic have left in root ssh access with one of the most widely used passwords in the world, and writeable rootfs, at least from what I've read on their forum. That means you can mess with it almost as much as you can with a Pi or similar. This is generally considered a bad thing from a security perspective, but a good thing if you want to mod your hardware (and change the root password to something more secure!)
Has anyone looked at what's needed to do firmware updates, and whether that's unlocked too? Assuming the hardware's not fundamentally broken, and that all the problems are in the software, this might allow a community firmware version that fixes the audio problems as well as the security issues.
There's a reason I don't entirely trust audio companies when it comes to device security - even the companies that specialise in network devices have a lamentable record on that front, especially in consumer devices. Take these recent investigations of devices from TP-Link and Netgear - the latter with an obvious backdoor and a possible 0-Day vulnerability that they're not revealing yet:
https://forum.level1techs.com/t/tp-link-be-800-red-team-teardown/250611
https://forum.level1techs.com/t/netgear-nighthawk-rs700s-red-team-level1diagnostic/250614