Having a unique password per device is best practices. IoT vendors should be doing that regardless of whether or not they're giving the end user root.
There's supposed to be a regulation demanding an IoT "nutrition label" that has that very thing in its list of items. I wonder what happened to that?