Not to understate the severity of this issue, but how is this any different than if I built a custom device that contained a USB hub + emulated HID keyboard to fire off a malicious macro + flash storage housed inside a plastic shell that looked like a normal flash drive? I guess that would require developing and manufacturing custom hardware.
So maybe it's not different. And this just significantly lowers the barriers to entry to an extremely easy process using only off the shelf hardware. And now the malicious device can be anything from flash drives to keyboards to USB Missile Launchers.
That seems like a problem the manufacturers need to resolve, however inconvenient it is to have read-only firmware.