Your Router Is the Weakest Device in Your House
By NorwegianSpark Editorial · Published August 8, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Every device in your home connects to the internet through one box, and it is almost always the one device nobody has touched since the day it was installed. Phones nag you to update. Laptops restart themselves. Routers just sit there, quietly running whatever firmware they shipped with, often for years.
That matters because a compromised router sits in front of everything. It can redirect the addresses your devices ask for, watch traffic that is not encrypted, and quietly add itself to a botnet without ever slowing your Netflix enough for you to notice.
The good news is that securing one is a ten-minute job you do once.
Change the admin password — not the Wi-Fi password
These are two different passwords and people mix them up constantly.
The Wi-Fi password is the one you give guests. The admin password is the one that logs into the router's own settings page. Many routers ship with a default admin login — often printed on a sticker, often the same across an entire product line, and always published online somewhere.
Log into your router (the address is usually on that same sticker, commonly 192.168.0.1 or 192.168.1.1) and change the admin password to something unique. If you keep a password manager, store it there.
Update the firmware, then turn on automatic updates
Router firmware receives security patches like anything else, and unlike your phone it usually will not install them unless you ask. Find the firmware or update section, install whatever is pending, and if there is an "automatic updates" option, switch it on.
If your router has not received an update in several years, it may be past its support window. Manufacturers stop patching consumer models surprisingly quickly, and an unsupported router is a permanent open door — that is the one case where replacing the hardware is genuinely the fix.
Turn off remote administration and WPS
Two settings are worth disabling on almost every home network:
- Remote administration (sometimes "remote management" or "WAN access") lets you reach the router's settings from outside your home. Very few people need this, and it exposes the login page to the entire internet.
- WPS, the one-button pairing feature, has known weaknesses in some implementations and saves you about fifteen seconds a year.
Use WPA3 if you have it, WPA2 if you do not
Check the wireless security setting. WPA3 is current; WPA2 is still acceptable. If you find WEP or an open network, change it immediately — WEP has been broken for many years and offers essentially no protection.
Put the smart gadgets on the guest network
Most routers offer a guest network, and it is more useful than the name suggests. Smart plugs, cameras, TVs and speakers are frequently the least-maintained devices in a house. Putting them on the guest network keeps them separated from the laptop with your tax returns on it.
Check the DNS settings, because that is where hijacking shows up
Every time a device asks for a website, something has to turn that name into an address. Your router usually tells every device on the network which server to ask.
Change that one setting and you can send every device in the house somewhere else without ever touching the devices themselves. It is the most valuable single change an attacker can make to a home router, which is why it is worth a look even on one you believe is fine.
Find the DNS or internet settings page and read what is listed. On most home networks it will be blank, set to "automatic", or set to your provider's servers — all normal. What you are looking for is an unfamiliar address you did not put there. If you find one and you did not deliberately configure a filtering service, reset the router to factory settings and configure it again from scratch, rather than simply correcting the entry. If something was able to change that, assume it changed other things too.
A worked example of how the easy version goes wrong
Take a household with a five-year-old router, still on the admin password printed on the sticker, remote management left on after a support call, and firmware last updated at the factory.
Nothing in what follows requires a skilled attacker. An automated scanner finds the exposed admin page. The default credentials for that model are in the manual, which is a public download. The login succeeds on the first attempt. The DNS entries are changed, and every phone, laptop and television in the house now resolves names through a server nobody there has heard of.
The residents notice nothing at all. Sites load, streaming works, speeds are normal. The only visible symptom might be an occasional certificate warning that gets clicked through because warnings are annoying.
Now change one thing in that story. With a unique admin password, the login fails and the sequence stops. With remote management switched off, the login page was never reachable to begin with. Either single setting breaks the whole chain, which is why the list below is short and why order barely matters.
What to check, in one pass
- The admin password — unique, stored in your password manager, not the one on the sticker
- Firmware version and date — install what is pending, then enable automatic updates
- Remote administration or WAN access — off
- WPS — off
- UPnP — fine to leave on if consoles or games need it, tidier off if nothing does
- Wireless security — WPA3 where available, WPA2 otherwise, never WEP or open
- DNS servers — blank, automatic, your provider's, or a filtering service you chose yourself
- The connected-devices list — anything you cannot identify is worth chasing down
- Guest network — enabled, with the smart gadgets moved onto it
If the router came from your provider
Most people never bought their router. It arrived in a box with the broadband, and that changes two things.
Some provider-supplied models restrict which settings you can reach, and a few hide the firmware page entirely because the provider pushes updates remotely. That is not automatically worse. A provider patching on your behalf is doing a job you would otherwise have to remember to do. It does mean there is less for you to check and less for you to control.
The awkward case is the provider router that is both locked down and no longer maintained. If you cannot change the admin password, cannot find a firmware date, and the model is years past release, the realistic options are to ask the provider for a current model or to run your own router behind theirs. Neither is a five-minute job, which is exactly why it is worth discovering now rather than during an incident.
The honest limits
None of this makes your network unbreakable, and none of it protects a device that is already compromised. A laptop that arrived with malware on it is still compromised on a perfectly configured network. What these steps do is remove the easy wins — default passwords, unpatched firmware, an exposed admin page — which is what opportunistic, automated attacks actually rely on.
There is a fair counter-argument, and it deserves stating rather than waving away. For a typical household, the realistic route to trouble is not the router. It is someone entering their password on a convincing fake login page, or reusing a password that leaked somewhere else entirely. Measured by how people actually get hurt, an hour spent on a password manager and two-factor authentication does more good than an hour spent in router settings.
The reason to do the router anyway is that it is a one-off. Password hygiene is a permanent habit that has to be maintained; the router is ten minutes and then a reminder twice a year. It is one of the very few security tasks that genuinely stays done.
Where this fits
Your router protects the network. It does nothing about what happens on the devices attached to it, which is why it sits alongside rather than instead of everything else: antivirus for the machines, a password manager for the accounts, and caution on networks you do not control, covered in staying safe on public Wi-Fi. If you have cameras, doorbells or smart plugs, securing those is the natural next step, since they are the devices you have just moved onto the guest network.
Set a calendar reminder to check for firmware updates twice a year. That, plus the steps above, puts you ahead of most homes on your street. If you want to go a step further and run a VPN on the router itself rather than on each device, our sister site VPNTex has the router VPN setup walkthrough. For the software side of the same house, what we actually recommend, and why covers what belongs on the machines behind that router.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.
Continue reading
privacy
They Did Not Steal Your Phone. They Stole Your Number.
A SIM swap moves your phone number to someone else, and every code sent to it goes with it. How the attack works, the warning sign, and why SMS is the weakest second factor.
privacy
Who Else Can See Your Security Camera?
A camera pointed at your living room is a camera pointed at your living room — the question is who can reach it. What actually goes wrong with home cameras, and the settings that matter.
guides
Antivirus Buying Guide 2026: How to Choose the Right One
How to choose antivirus in 2026: the features that matter, how to read lab scores, how many devices you need, and the pricing traps to avoid.
