Turning off the remote-web-management interface by default at factory at least? This will mitigate the issue, still nobody should ever pre-program the fixed root password, or at least with BOLD FONTS asking customer to change it right away, or better, force people to set up a password during installation time.