Notably, the backdoor uploads data to an NFS share hosted on a university IP (the exact university has not been made clear). Data includes patient names, doctor names, date of birth, and the specific hospital department the patient is at.
https://contechealth.com/pages/company-introduction
I doubt it.
If you think the FDA or other regulating bodies wouldn't immediately tell care providers to yank these devices, you might be in for a surprise.
What's more mysterious to me is why there's a back door in a device like this. Seems like a bizarre way to attack your enemy.
It almost makes me wonder if there's a component in the hardware or software that's shared with other devices manufactured in China that are better attack vectors and they just tossed it into this one because, hey, it works.
That backdoor, if it reports to a university, is probably put there to facilitate a study/diploma/phd or something like that.