There is no real harm in having every port open if he just pipes the inbound data to /dev/null -- but it doesn't make sense either. Network security in general is based on implementation of individual devices so its hard to say whether or not this will be a problem.
As far as the data being sent as plaintext -- I don't see how that poses a security concern unless you have private information being transferred such as passwords or company information? You could always use a VPN tunnel and encrypt the connection to your home office since you do not control the device comms.
sknake
Industrious Poster
4,954 posts since Feb 2009
Reputation Points: 1,764
Solved Threads: 735