There's a big issue with quality on devices but spreading conspiracy theories only harms that cause. There's no reason to believe this is connected to a government — and it's way below the level of craft we've seen in that regard – and making dubious claims is more likely to cause people to take you and the broader argument less seriously.
> This situation has been a problem for years now. What can be done? What regulation or law would help? What should we demand?
Two good starting points would be protection for security researchers and the requirement that manufacturers promptly support devices for a reasonable amount of time. Things like this happen because there's very little perceived cost to shipping something shoddy compared with not getting as many features to market as quickly as possible.
A followup point, especially for restoring trust that there aren't sophisticated backdoors, would be not just source code but fully reproducible, user-installable builds. This is still fundamentally a losing game if you don't trust the hardware but it'd dramatically increase the odds of someone being able to notice an error, not to mention being a huge win for users’ ability to improve an orphaned device.
The reason why that's unlikely to happen is that companies treat source code as a significant asset, which is why I first mentioned a longer support period. My favorite approach for this problem would be regulation requiring mandatory release of source code, the toolchain, signing keys, etc. if the manufacturer stops supporting something, so the places which want to keep their trade secrets can still do so but are required to help their users at the same time.