Where passwords are used and in any state other than the factory default, all consumer IoT device passwords shall be unique per device or defined by the user. Pre-installed unique per-device passwords shall be generated by a mechanism that reduces the risk of automated attacks against a class or type of device.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.