This is how Equifax was "hacked". They had a remote server with those credentials, which someone used to steal all our info. Equifax paid like $10 per person in fines and said "teehee our bad".
At least now the default settings on most routers include a unique WiFi password printed on the router, so either that password, physical access to the router, or a serious security vulnerability in software that never receives updates (gee, this list is getting long) is necessary to compromise the router.
I remember seeing this in at least one Linux distro (I think it was Bunsenlabs but I'm not sure, might be something like Kali but I never used that one) a few years ago, nowadays they just give the live account passwordless sudo and lock the root account unless you pick a password for it