Which doesn’t matter about the password. If you have a faulty router which allows unauthorised inbound connections then you have a bigger problem than weak credentials
huh? The camera pokes the hole in the "firewall" (NAT in 99% of cases, which isn't a firewall, hence why it's so easy for bits of software to poke holes in it.
You don't even need to do UPnP, if you're okay with a random port, you can just do STUN.
Some cameras do also open ports with UPnP but it's rare in my experience. I think these cams are more users who are a bit technical but not too much to realise the implications.
Well this very site is why it's bad. And things like Shodan.
It's the swiss cheese model. I'm sure most of these people didn't mean to make their cam accessible to the internet. If there had been a unique username/pw they wouldn't have got exposed.