I realized the password on the wire problem after posting. The solution is the following.
A host with a vlan directly to the device, so password isn't on the a sniffable wire. Use a cgi form to fill in information from operator, and then run commands on secured host.