Knowing NXP and how much they value SW development, they most likely off-shored this to the cheapest possible sweatshop and that's the result, no need to look to deep into it, it's just how it works over there.
Meh, the financial industry has bigger password shenanigans that NXP's dumb form.
It has been awhile (about 10 years or so), but I can recall at least two widely used enterprise access management systems that had trouble with some special characters. Access management is hard. Even those able to pour boatloads of cash into it don't necessarily get great results. On the other hand, there's nothing hard about providing users with a clear statement of your system's limitations. What ever happened to UAT?