AMX, which supplies communications kit for the White House, US military, and several of the largest corporations, built a superhero-themed surveillance backdoor into its products.
An analysis of the AMX NX-1200 communications controller by researchers at SEC Consult showed the device had a "setUpSubtleUserAccount" function.
It turns out this does exactly what it says – it sets up a hidden account with special abilities not even given to an administrator, such as packet-capture and sniffing, as well as access to the network interface. This powerful, all-seeing account can be accessed via the device's built-in web interface or via SSH using a hardcoded password.
That's a major issue, particularly because the US President has been seen using AMX equipment to talk to his military advisors.