I saw this on /r/netsec a few days ago. One of the comments there mentioned that some POS devices are still vulnerable to the VNC authentication bypass exploit from 2006. The "we lose money if we patch"/"don't have time to patch, got this stuff to do" mentality is strong with this one.