I think the problem is that the typical engineers that work on these devices are used to work on a whole different layer - hardware. But they know how to put together a few simple CGI scripts and probably don't even know the dangers they are facing when they run HTTP(s) server.
So on the one side you have HW guys saying "no need to find someone, we can do it ourselves" and on the other managers gladly accepting this on face value (it probably does cost them less in the short run). I am not saying these guys are not good engineers, just that this is not their area of expertize. Their mistake is not realizing this.
I've worked in embedded devices, and the problem isn't that the engineers don't know how to fix it properly, it's just that nobody cares enough to make consumer-level devices very secure. That costs money.
So on the one side you have HW guys saying "no need to find someone, we can do it ourselves" and on the other managers gladly accepting this on face value (it probably does cost them less in the short run). I am not saying these guys are not good engineers, just that this is not their area of expertize. Their mistake is not realizing this.