They could at least try harder to cover the new access method. I really wonder why they did not. They should have assumed that this particular backdoor will be disclosed. So even in the event of having legitmate use cases for access like this they still decided to endager their customers.