A bit more detail about the behaviour:
Scenario:
Box has IPv4 192.168.178.25/24 (That means IPv4 192.168.178.25 inside a /24 subnet, which equals network 192.168.178.0 with a 255.255.255.0 netmask).
You also have a guest WLAN/LAN running with network 192.168.180.0/24 and a remote LAN with network 192.168.1.0/24 connected through a VPN.
Box also has IPv6 2001:db8:affe:1:0212:34ff:fe56:789a/64
Default behaviour ("Access from VPNs allowed" = no):
Even with auth disabled, OWIF will accept connections from the box' own networks 192.168.178.0/24 and 2001:db8:affe:1::/64, but not from any other network.
Behaviour with "Access from VPNs allowed" = yes:
Even with auth disabled, OWIF will accept connections from all private address space, meaning
192.168/16
172.16/12
10/8
fc00::/7
this includes, but is not limited to, the network 192.168.178.0/24 ... it also includes your VPN connected remote LAN 192.168.1.0/24 but also the guest (W)LAN 192.168.180.0/24, as they are both in private IPv4 address space from 192.168/16.
and connections from the same subnet, in this case 2001:db8:affe:1::/64, plus all IPv6 private space (ULA) from fc00::/7.
With auth, access is possible from everywhere (once allowed in your router/firewall), but it is strongly discouraged to use it for direct external access even with auth.
Passwords for HTTP are sent in plain text (unencrypted) and can be recorded from anyone in the same network (connected to the same WiFi hotspot for example).
OWIF only enforces the bare minimum "protection", it is still mostly optimized for convenience or rather laziness.
Keep in mind that OWIF without auth can already be used to bypass the pin protection on XXX channels through streaming or gain full control - incl. reading that PIN - by injecting new IPK packages through OWIFs package manager.
Please think twice if it's really too much demanded to set a password for user root or better create a new user on the box and enable auth.
I really don't get the problem that many users appear to have with it, I have done it from day one with an E2 box on as having a Linux system without a password set simply feels wrong.