Ultimately this blog post doesn't describe any rocket science at all: anyone wanting to cause trouble on the internet is well aware of Shodanning for exposed ICS systems that fail to even implement authentication.
Anyway, call me old-fashioned, I don't think this is the way it should be done.
FWIW I'm aware of a SCADA system that is widely deployed that is just about as secure as this system here and I'd be the last person on the planet to publish the details of it because I know for a fact that it is used to control HVAC equipment and other building infrastructure in hospitals and prisons. These things are not toys and being aware of them does not actually allow you to play god. (In that particular case as far as I know the systems are so old that fixing them with an update is not even an option).
If releasing irresponsibly a vulnerability puts people in real danger, is it worth it to suppress the release of that vulnerability?
Yes, you and a cool bunch of Chinese and Russian government-hired hackers, too.
http://www.neweagle.net/ProductDocumentation/Telematics/Tele... mentions "Remote Flashing" so I guess they fix that.
I'm going to go with "no". Companies that admit their failings to their customers are probably pretty rare, particularly "companies that will fail to attempt to secure their computer systems but will actively engage their customers when an issue becomes the focus of unwanted attention" must be close to zero in number.
This is not really a bug, this an unfit design.