Basic analysis: runs VxWorks.
Thorough analysis: I have been unable to decrypt the main firmware payload, as for any other model. No help there. It does have the strings EnableBootDisk and DisableBootDisk, so I think it's possible to modify the flasher to execute EnableBootDisk, after which booting with AUTOEXEC.BIN should work. I guess that's as useful as it gets.