The MCU is able to program its own BT subsystem (by any set of commands) - why is this the backdoor ?
"Backdoor" term: IMHO, it's the hidden way to avoid the preinstalled authentication method by an intruder in the publicly available IT system.
MCU firmware is not publicly available anyway.
If you have direct access to the MCU re-flashing: who cares which commands set is used for programming the MCU (or its BT subsystem) ?