This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.
That sounds like they just erroneously left AllowRootLogins yes in the ssd_config, which would not be a critical vulnerability.