Synology active backup for 365 vulnerability

What are your thoughts on this vulnerability?

That Synology did a dumb in how they implemented it but did fix it.