A default password scales into a fleet vulnerability

One default credential on one device is a small problem. The same credential on ten thousand deployed devices is a systemic one.

That is what makes factory defaults different from an ordinary weak password: it is not a mistake somebody made, it is a property of the product. The UK now prohibits universal default passwords on consumer connected devices for exactly this reason.

More on IoT and embedded