("admin/admin" or similar). If these aren't changed, an attacker can literally just log in. Typically the Mirai botnet in 2016 famously contaminated millions of IoT devices by simply trying a directory of arrears passwords for gadgets like routers and cameras, since consumers rarely changed all of them. - Directory