A bug in the Promise NAS NS4300N web GUI allows an authenticated (admin) user to change the password of the 'root' account.

http://www.securiteam.com/unixfocus/6F0030KK0O.html