The security level should be the user's choice. Maybe I don't care if my neopets account is hacked. Maybe the 2fa offered actually decreases security, like the SMS 2FA required by my 401k account that can be used as the sole recovery factor, bypassing the password. Maybe I'm accessing from a system configuration that makes 2fa really annoying, like a build system running inside a fresh VM on every run.
The service doesn't have the context necessary to know when 2FA is warranted.
It means the manufacturer is required to offer to buy it back. If the manufacturer resells it after fixing the issues, there must be paperwork attached and given to the next purchasers stating that it was a lemon.