If they get into a vulnerable device on your network and you have weak network security they can dictionary attack into the network. Or if you have UPNP enabled it’s already done. From there any device connected is compromised
To add on, create a separate network with WPA3 for your more sensitive devices and keep those IOT devices on their own network
Just like a chain, strength is determined by the weakest link
Use secure passphrase for ALL your devices on your network
If they get into a vulnerable device on your network and you have weak network security they can dictionary attack into the network. Or if you have UPNP enabled it’s already done. From there any device connected is compromised