I am having the same problem.
Under ‘Login Security Options’ I have selected ‘Force all members to use strong passwords’. But when the link is sent, I can override the strong default password with something ‘very weak’ like ‘cat’. The message ‘Your password has been reset. Log in’ then appears and I’m able to then log in using this very weak password. The example user is a Subscriber.
Thanks.
Andy