Security neophyte here- you are exactly right. It also seems like in this case there was a "default encryption key" and is 100% a part of the problem
I do work with OSDP devices and I have heard this argument from manufactures, like "we only support setting a new key while using the default key, it's more secure that way". While it, at best, will just obfuscate the process.