Hackers don't care
Hackers don't care if they should not go further, so why should pen testers.If a pen tester gains higher level privileges and they do not mess with or alter anything and report what they have done and how they did it then they should be rewarded. Just because the flaw was not software or code based does not remove the fact that it was a flaw, and a massive flaw at that.
I for one am glad that he found this flaw and informed facebook. How many other people found the "keys to the Kingdom" as I've heard this hack call in other articles.
It seems like a very lax approach to security to allow staff to have weak passwords set for any account or service on their domain. Have these staff members been fired, or at least reprimanded ?
A hacker is not going to sit there and be like "O look i cracked these weak passwords, but I better not go any further"