The article is clear that they were able to replay messages. So even adding authentication by itself wouldn't be enough to prevent simple replay attacks. They would need to update the protocol to add "freshness", e.g., some kind of counter, timestamp or nonce that prevents the acceptance of recorded messages.
This is actually a huge upgrade, given that there are so many receivers. It's one of those "really, really bad but probably won't be abused until we're in the midst of an actual kinetic conflict" things. But then again, we're moving into a world where infrastructure gets attacked even during "peacetime."