This isn’t the first occurrence and it sure won’t be the last, either.
Hospira Lifecare PCA infusion pump running “SW ver 412” does not require authentication for Telnet sessions, which allows remote attackers to gain root privileges via TCP port 23.
Imagine having an infusion pump that someone can remotely control. Power on, power of? Increase or decrease the supply?
How is security not a top priority for anything medically related? Even remote surgery equipment (the actual robotics hands someone can control from the other side of the world) has known security issues.