How reasonable do you think it is to be this automatically suspicious of any computer coming from China? A generic low-cost barebones Intel PC certainly has plenty of space for compromised firmware to hide, but it's implausible that a Chinese intelligence agency would indiscriminately deploy an attack that made use of a compromised Intel Management Engine firmware signing key to put firmware rootkits in cheap hardware sold to individual consumers.
On an embedded system like the OpenWRT Two where the entire BOM of the system will be public and the OS has full control over the raw flash memory, a purely software-based supply chain attack would be extremely difficult, and a hardware-based supply chain attack would be expensive. Do you think an intelligence agency would really bother with this for a device that is mostly going to be shipping to nerdy hobbyists?
There's more to a threat model than just recognizing that an attack may be technically feasible.