The latest generations of servers ship with randomized BMC passwords. This was indeed a problem in the past when they shipped with credientials such as ADMIN / ADMIN or no password at all.
But yes, some providers put the BMC on the internet because it's easier, a provider I used once did this and I was quite displeased as iDRAC's are quite weak and suffer under the weight of bot-spam. -- even if there were no security issues.
It’s nice to slide in a server, watch as the arps/dhcp requests go out and see the machine spring to life without human intervention.
Easier if there’s a known username/password.
It was printed on a slide out tag.
Some earlier generations had paper/cardboard tags tied to them I think but I cannot remember if passwords were there.