We’ve been warning about this for literally three decades, ever since CALEA mandated wiretap-ready telecom infrastructure. And this is merely the latest example of how these dangerous interfaces can be turned against us by our adversaries. https://mastodon.social/@fj/113253726161428151
Exploits of "lawful access" interfaces, such as the Chinese attack reported today by the WSJ, appeared almost immediately after they became standardized in the 90's. The most famous example is the case known as "the Athens Affair" https://spectrum.ieee.org/the-athens-affair .
Also, I'd be remiss if I didn't note that all the reasons that "lawful access" features in telecom infrastructure are risky apply at least equally to the periodically revived proposals for "key escrow" backdoors in cryptographic systems. Fortunately, we've mostly held back the tide on those, but they come up every few years. It would be a security disaster if they're ever mandated.
The Athens Affair is interesting for a number of reasons, but it's particularly notable that the switch that was compromised didn't actually have the CALEA option installed from the factory (since it wasn't then required in Greece). But it was added through a software update (induced by the attacker), and then exploited.