Filters apply as you choose them.
In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.