What it means
Firewall misconfiguration is not always dramatic. It may be an any-any rule added during troubleshooting, a port forward left open after a vendor project, or a management page reachable from the public internet.
The risk is that the firewall stops representing business intent. Instead of allowing only required traffic, it permits traffic nobody has reviewed recently.