People make well-meaning assumptions about security. For example, most of the oscilloscopes that we use at work have remote access turned on with a trivial password (the scopes themselves run windows, and have a VNC server installed [1]).
If you go read Tektronix's instructions - their screenshots show "no authentication" selected.
This itself isn't really an issue, since the networks that we're connecting these to are isolated, inbound-only lab networks. We know that. Our lab admins know that. The network security guys know that. There are exceptions filed for the IPs of these devices.
However, if someone ever -changed- that network configuration and opened it up to the rest of the corporate network (or for some terrible reason, the internet), those scopes would be just as ripe for takedown as the stuff shown in TFA.
It just takes that small network change to enable something -else- to access the WWW (code download for security updates, anyone?) that exposes our other items on the network. In fact, I can think of several reasons why someone might expose a VNC:
1. Actual remote control -within- a facility, but probably in the deployment guide says "use a secure network"
2. Someone wrote a cool Web GUI to "modernize" something, and used VNC (undocumented and poorly-configured) to pull off what they pulled off
3. Someone exposed a subnet to the internet to enable remote access for something -else- which was probably properly-secured, but happened to -also- expose the thing hosting the VNC server.
[1] http://www.tek.com/support/faqs/how-do-you-set-vnc-dpo7000-d...