Seriously, they're just too lazy to auto-generate firewall rules from their list of assigned addresses.
I think vendors also have some responsibility. The defaults are bad and the vendors make their devices hard to manage on purpose (for lock-in reasons). I'm looking at Cisco in particular.
Seriously, they're just too lazy to auto-generate firewall rules from their list of assigned addresses.