FYI Zyxel consumer switches seem to be more secure in this regard (I had a GS1200).
But yeah, even the enterprisey switches have braindead defaults like loading configuration from tftp at startup.