I couldn't find the text in the act that actually did anything related to what the article states it does. I looked to see if it hadn't just banned weak default passwords but banned default passwords entirely. That is that each device must have its own randomly generated passwords which are generated by another computer with sufficient entropy after the firmware is written to the device.