Cyber Security

Securing Your Router: Why Default Wi-Fi Passwords are a Hacker’s Best Friend

Securing Your Router: Why Default Wi-Fi Passwords are a Hacker's Best Friend

Your home router is the gatekeeper for phones, laptops, cameras, TVs and smart devices. If its administrator password or Wi-Fi credentials are still the defaults supplied by the manufacturer or internet provider, you are leaving an avoidable weakness in the network. The FTC recommends changing default router settings, using strong unique credentials, enabling encryption and keeping router software updated. CISA guidance likewise recommends changing default router and Wi-Fi passwords and using WPA2 or WPA3 encryption.

Router password and Wi-Fi password are not the same thing

Many people change the Wi-Fi password but forget the router’s administrator password. The Wi-Fi password controls who can join the wireless network. The administrator password controls the router settings themselves. Both deserve unique, strong credentials.

CRM for small business

Why default credentials are risky

Default usernames and passwords can be predictable, reused across models or printed on the device. Even when a default credential is not publicly obvious, keeping it unchanged gives an attacker one less barrier if they gain access to the local network or administration interface. Reusing a password from another account creates a second risk because credentials leaked elsewhere can be tried against the router.

5 router security settings to change

  1. Change the administrator password. Use a long, unique password and do not reuse one from email, banking or social media.
  2. Change the Wi-Fi password. Use a strong passphrase that is not based on your name, address or phone number.
  3. Use WPA2 or WPA3. Avoid legacy wireless security such as WEP where it is still offered.
  4. Update router firmware. Install updates supplied by the manufacturer or provider and enable automatic updates when supported.
  5. Disable remote administration unless you genuinely need it. Managing the router from the internet increases the attack surface and should not be left enabled casually.

Give guests their own network

If your router supports a guest network, use it for visitors and less-trusted devices where practical. A separate guest network can reduce unnecessary access to the devices connected to your main network. It is particularly useful when you have smart TVs, cameras, appliances or other IoT devices that do not need to communicate with your work computers.

Audit the devices connected to your Wi-Fi

Open the router’s device/client list and look for phones, laptops, TVs, printers and smart-home products you recognize. An unknown device does not automatically mean you have been hacked—it could be a familiar device with an unexpected name—but it is worth investigating. Remove old devices and change the Wi-Fi password if you believe someone has unauthorized access.

What not to do

  • Do not use “12345678,” your mobile number or your house address as the Wi-Fi password.
  • Do not use the same password for the router and your email or banking account.
  • Do not leave WEP or similarly obsolete security enabled for convenience.
  • Do not expose the router administration page to the internet unless there is a specific, well-understood reason.

Related PURSHOLOGY resources

For broader security hygiene, see our SSH security mistakes guide, fake software update fraud article, and cybersecurity compliance tools guide.

Sources