Given the prevalence in enterprise networking equipment of undocumented admin accounts, you need to manage the risk when the vendor itself is the one getting direct manager service access.
The lack of technical layer logs is a concern, but these logs also need to be independent and generated by equipment from a different vendor - it would be easy to (for example) not log any received command packets with the TCP evil bit set. An external logging system from another vendor would detect this.
Unfortunately mobile core networks are often relatively limited in vendor diversity, so it's possible you won't have this in place.