First of all, LMFAO.
By failing to authenticate three times to an unconfigured Abilis CPX device via SSH, an attacker can login to a restricted shell on the fourth attempt, and from there, relay connections.
Second, it's been a while since I've noticed @hdm and @todb on a new CVE.