For something like SSH which has authentication and authorization as features, I would expect to talk about an RCE in that context, and not the backdoor’s auth features.
This backdoor bypasses both authentication (not requiring an account password, authorized key, etc on the target system) as well as authorization (as it doesn’t check a user against any policy for what commands or users can log in).
Remote code execution means a single thing, running JavaScript when accessing a web page and using SSH as intended is not RCE.
The links you point to there are about "RCE attack" which also implies not authorized.
> in the introductory paragraph it reads "unauthenticated, targeted remote code execution ... I believe this means it was unauthorized, not unauthenticated.
You again:
> agree that RCE, unqualified, means unauthorized RCE
So you agree that your "unauthorized" qualification from your orignal post was unwarranted, since all unqualified RCE are unauthorized.
Now if you want to split hairs, you'll say "but the introductory paragraph said unauthenticated, which is qualified RCE, thus I am still right". ok then
All RCEs are classified in either unauthenticated or authenticated, the former being the worst (or best if you're a researcher/hacker).