Is this an actual backdoor, as in, put in there on purpose by the manufacturer? Sure sounds like it.
Static key, decrypts all cards of a given model regardless of user stored keys? Yep, it's a backdoor.
> put in there on purpose by the manufacturer
Hard to prove "on purpose" either way, my guess it was for debugging.
(but hey, taking Croudstrike into account, everything is possible)
Even the ones not made by a Chinese company had the same backdoor. Perhaps, the original design had this backdoor and the manufacturers simply implemented the design. NXP is Dutch. Infineon is German.
So if the code was there it's not the fault of the card manufacturer but the applet developer.