https://www.theregister.co.uk/2019/05/02/cisco_vulnerabiliti...
The other possible explanation is that it's intentional.
I picture their code coming in as .zip email attachments from whatever outsourcing company, and landing on an NFS share somewhere. I’d be impressed if they had version control, let alone code review.
https://www.theregister.co.uk/2019/05/02/cisco_vulnerabiliti...