I worked with those devices. Things like icmp responses and ttl expired packet make it to the control plane cpu iirc. I was thinking more of a worm that would gain access to everything via internet exchanges ,propagatig through bgp sessions and such. Also, didn't know those backdoors in zte/huawei were a thing. But they do tend to have hardcoded creds "for support".
If you have a router that exposes its admin/control plane/routing engine interface to IX and BGP peer facing addresses, that's another fundamental network architecture problem to address before worrying about anything else. Management VRFs, ACLs, etc. There should be absolutely no way to get the routing engine/control OS to listen on any interface facing anything public...
Yeah,one provider does that to the net,exposing their network which includes their IX router which connects to your IX router which connects to the IX lan. Heck,a well resourced attacker can peer with you on the IX lan just so he can attack you.