I also find it suspicious, that the attacker would have needed access to a database of the device UIDs (factory metadata) to perform the attack.
"The software PRNG was seeded from non-secret values — the MCU's chip serial number (UID) and timer/clock registers — none of which are cryptographic ...