I'm not sure what bbs software they were using

It was vBulletin.

I can only guess the hacker cracked an administrators password.

Some exploits don't require password-cracking to gain root privileges. In fact, most hackers don't even bother cracking passwords until after they've already gotten root privileges via another exploit. After that, they grab all the password files on the system.
Tony Fabris