I work with industrial HSMs (those expensive ones) on a daily basis and their SDKs are a bugfest (both client side and in-device). They are audited (FIPS140-2 and now 3 approved even!) but apperantly testing the firmware against the test vectors from the RFCs is too much too ask for... Contacting support about broken firmware or broken documentation is a trip to tartarus in itself. Decompiling the libraries is usuall…
It literally means it hasn't been receiving regular security patches/updates!