Why would there be a need to upgrade the kernel? Security updates are often backported, so it can still be 5.10 but patched...
So long as they keep up with patches that can be fine, but newer kernels also have useful feature improvements. If nothing else, performance tends to improve over time.
It could be, but are vendors actually upgrading kernels along with firmware updates? In my experience it's more like, ship 5+ year old kernel and then forget it forever.