Why would someone comment out authentication for reset? I mean, what possible reason is there for doing so? It doesn't make security any better and it's not something which impacts day-to-day performance in any way.
The most infuriating answer would be maybe they were testing the restore function, and was tired of entering the test username and password over and over again. And then the "I'll just comment it out for my tests" got commited, and built, and deployed.
If a user forgets their password, they still need a way to factory reset so as not to brick the device. Of course, this should involve, say pressing and holding physical button on the device. Just commenting out the password check was probably a lot easier.
Guessing this is right. While neither would be perfect, they could have at least checked for "request coming from the same local subnet" or "enter MAC address as password", or similar.
Afaik these devices do have a physical reset pinhole button.
If one of these devices is sold, the new owner may want or need to do a reset but doesn't know the password.
There exists a physical reset pinhole button on these devices.
Was likely done in development by a developer that was sick of seeing the same password prompt 50 times a day, and who later forgot to un-comment it. There's absolutely no way this should have made it past code review.