Sure it's a password written on the device, but it's random, you need physical access to see it, and people who are security conscious can change it.
This bad practice isn't excusable, especially not by a company as big as Huawai, not if they want to be taken seriously.
Enterprise equipment is usually not supposed to be just dropped into place, without oversight. It usually needs proper configuration/management, by qualified people.
Whether this also happens in practice can be a different story altogether. Still, the security of enterprise equipment usually involves more policy and procedure than it does with consumer equipment. With the latter, security has to come more or less by default, because the people handling the devices usually have little expert knowledge.
When you get a new device, in order to save your initial configuration on it, you have to set a password.
Cisco used to ship with zero config on their devices and part of the setup process was setting a password as well.
Later versions did not allow passwordless ssh but still allowed it via telnet. Cisco’s ACI platform enforces password on the initial account, then with some smarts you could disable it in OpenLDAP