I simplified the concept which might seem misleading to you but the outcome is exactly the same.
You can get access to the home network through weakly secured devices. If you can get past a weak device, trusted by the network, you can send commands through the network and to other devices as if you were a typical user. If your car can be unlocked from your computer (or phone) over the network, a hacker would only need to get past your coffee maker on that same network to be able to tell your car to unlock.
In other words, the Internet of Things can often be a liability if you don't know how to secure points of access to your network. If you installed a smart thermostat and it's still broadcasting the default SSID, that's a glowing weakspot for a hacker. Who would need WPA2 security for that, right?