>write to the kernel area of flash

It's possible, in a convoluted fashion, beyond most script kiddies. But it's also relatively harmless, and easy to fix.

>change the running order (e.g. HTTP "play")

There's a play button in emplode (replaces running order).

>Remove or replace files outside of the music partions
>(e.g. the player binary), other than config.ini

But the files on the music partitions are the most important ones. All of the others can be restored to original state with a player upgrade. Music theft, substitution, playlist deletion.. those are the real issues to worry about.
