Yes, I would expect that to be true because there does not seem to be any kind of SSL/HTTPS mechanism implemented.
I keep my Cisco login information (password) quite different from what I use for other access. In fact, that is true for almost ANY web-based public system.