Back when every telco was a quasi-governmental national operation, they could all more or less trust each other to do the right thing, so when one network operator receives information from another (for example, caller ID info) it just blindly trusts it as correct.
We've layered tons of modern digital services on top in the last decades but fundamentally there's still that very old network with very basic capabilities underpinning it all.
And so in today's world where every telco offers wholesale access to resellers (who then have sub-resellers and sub-sub-resellers) it's almost impossible to police this stuff.
There's so much traffic going through these networks, it would be very expensive to stop and validate/verify every call's metadata, even though there have been proposals on how to do that put on the table by various parties for years.
But telcos are competitors, and getting them together to agree on how to handle this kind of thing is hard. No one can agree on who should pay for it, and no one wants to go first. Every telco basically passes the buck. So if you are on Verizon and you get a fake caller ID spam call, Verizon will say "we're just forwarding the call from X, go complain to X".
There has been some legislation passed in the last few years as the problem has gotten worse, but don't expect telcos to move on any of this until forced to by law.
source: I work for a telco.