From personal experience (I guess now that the statue of limitations has passed..) I was part of a large community of people in the not so distant past hacking into cable ISPs. Small ones were easy to bypass security mechanisms and spoof other customers devices or simply trick their servers into issuing valid configs, but obviously there was the one big one that I’m sure everyone has heard of. Anyway, before the community was shut down, in the quest to defeat the more stringent security mechanisms, a few folks figured out how to jump from modems to an internal VLAN, got access to privileged SNMP communities and eventually owned the entire network starting at the head ends and eventually made their way to the core routers (Of course, the provider used the same credentials for everything, in an industry that to this day doesn’t use 2FA). Eventually the community was shut down. However, said ISP never acknowledged the breach. If some hobbyists could figure it out, I guarantee that nation-states can do it.