Do what the professionals do, read the data sheets and compare the models based on the features you want, then pick the cheapest one that will do the job (taking into account possible future expansion).
Any company that would hard code the default password into the software and then tell everyone not to change it is too freaking stupid to make a decent product. Stuxnet may only affect Iran's enrichment program but now that the security hole has been exposed, someone will exploit it for other purposes.there is already another stuxnet variant in the wild that is apparently doing reconnaissance. It too appears to be from the same source code library so it is not likely to be a third party knockoff, but rest assured one is coming down the pike.