In this case, we might say that the manufacturer has a much stronger responsibility to keep their devices under control than in the case of, say, a typical PC where the user assumes more of that responsibility. The less freedom you give your users, the more power you reserve for yourself. That power should come with corresponding responsibilities.
For example:
- Mandatory security auditing of all pre-installed software
- Mandatory security updates for X years
- Mandatory insurance for damages caused by vulnerabilities in your products
Allow some of these requirements to be met by reusing previously audited and/or independently maintained software, giving manufacturers an incentive to stick with well-tested standard components. Waive some or all of the requirements if the device is allowed to be used as a general-purpose computer and/or all the software is freely available.
Best case scenario: we get routers and TVs labeled "Red Hat Embedded Linux inside: security updates guaranteed for 10 years."