Re: They will never learn.
Cisco keeps laying off teams and moving the work to entirely new teams with no experience on the code base. Old lessons learned the hard way keep getting forgotten as a result. New teams don't even know/care about the design, process, engineering/QA docs stored for ISO 9001 compliance, and proceed to violate process and start breaking the product. This happened to a couple of my old projects. On one of them, got contacted by the new manager trying to figure out why the new team was f'ing up so badly. Asked him if they were following the docs for that project (docs that had passed an ISO audit with no findings no less), he went "what docs?" Ugh, REALLY?
With that said, NOTHING excuses something as stupid as a hardcoded anything in code, especially around user id's. Its got to be either a new hire, an intern (that haven't been through yearly Cisco security training), an engineer waiting to get laid off that no longer gives a rats, OR an intentional backdoor. I'd also list it as a failure in the design and code review processes which also should have caught this.