Your Router Is the Weakest Device in Your House
By NorwegianSpark Editorial · Published August 8, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Every device in your home connects to the internet through one box, and it is almost always the one device nobody has touched since the day it was installed. Phones nag you to update. Laptops restart themselves. Routers just sit there, quietly running whatever firmware they shipped with, often for years.
That matters because a compromised router sits in front of everything. It can redirect the addresses your devices ask for, watch traffic that is not encrypted, and quietly add itself to a botnet without ever slowing your Netflix enough for you to notice.
The good news is that securing one is a ten-minute job you do once.
Change the admin password — not the Wi-Fi password
These are two different passwords and people mix them up constantly.
The Wi-Fi password is the one you give guests. The admin password is the one that logs into the router's own settings page. Many routers ship with a default admin login — often printed on a sticker, often the same across an entire product line, and always published online somewhere.
Log into your router (the address is usually on that same sticker, commonly 192.168.0.1 or 192.168.1.1) and change the admin password to something unique. If you keep a password manager, store it there.
Update the firmware, then turn on automatic updates
Router firmware receives security patches like anything else, and unlike your phone it usually will not install them unless you ask. Find the firmware or update section, install whatever is pending, and if there is an "automatic updates" option, switch it on.
If your router has not received an update in several years, it may be past its support window. Manufacturers stop patching consumer models surprisingly quickly, and an unsupported router is a permanent open door — that is the one case where replacing the hardware is genuinely the fix.
Turn off remote administration and WPS
Two settings are worth disabling on almost every home network:
- Remote administration (sometimes "remote management" or "WAN access") lets you reach the router's settings from outside your home. Very few people need this, and it exposes the login page to the entire internet.
- WPS, the one-button pairing feature, has known weaknesses in some implementations and saves you about fifteen seconds a year.
Use WPA3 if you have it, WPA2 if you do not
Check the wireless security setting. WPA3 is current; WPA2 is still acceptable. If you find WEP or an open network, change it immediately — WEP has been broken for many years and offers essentially no protection.
Put the smart gadgets on the guest network
Most routers offer a guest network, and it is more useful than the name suggests. Smart plugs, cameras, TVs and speakers are frequently the least-maintained devices in a house. Putting them on the guest network keeps them separated from the laptop with your tax returns on it.
The honest limits
None of this makes your network unbreakable, and none of it protects a device that is already compromised. What it does is remove the easy wins — default passwords, unpatched firmware, an exposed admin page — which is what opportunistic attacks actually rely on.
Set a calendar reminder to check for firmware updates twice a year. That, plus the steps above, puts you ahead of most homes on your street.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.