As a couple of reddit commenters point out, the user agent string that bypasses auth (according to the post) can be read backwards as "Edit by 04882 Joel Backdoor", and one possible Joel is CTO Alpha Networks, whose thttpd this appears to be.
I've no security expertise, but this seems cataclysmically bad!