It shouldn't count as a vulnerability that you can get root of a device that you have physical possession of. If there's any real vulnerability here, it's that having root of your terminal gives you any extra privileges to the rest of the network.
That said it is a clever approach and it’s good it was discovered by someone without nefarious intentions.