Pfsense Webgui with login attempts

I was inspecting a clients pfsense web gui logs and noticed this below. I logged into the DHCP server and confirmed its a personal android phone on the network. Is the device infected? Never seen anything like this.

The rest of the attempts are all PRTG and windows server which is not unusual.

Is the device on a seperate network to the main network, if so block pfsense management access on this network - this is good pratice

Mobile devices should be classified as IOT , and have their own network