It always amazes me that we continually release software with these backdoors in them. What is the thought process that's going on? Do they think security by obscurity really works? They must or else they wouldn't keep doing this. Cisco isn't a small company, they have the people-power, processes, and money to not do this. It literally saves no time or money when you figure in the cost to fixing the issue. US government conspiracy theories aside, I'm guessing it's just lazy developers, incompetent managers, or potentially intentional maliciousness from foreign governments or competitors.