Home

How to secure and maintain your wifi router

Buyer Reports Editorial
Updated 2026-08-08
Key takeaways
  • Change both router passwords: the admin login and the Wi-Fi network password are separate credentials, and the FTC recommends resetting both from their factory defaults.
  • Use WPA3 Personal if your router supports it, or WPA2 Personal (AES) as the fallback; both CISA and the FTC list these as the current standard, with WPA2 still acceptable where WPA3 isn't available.
  • Check for firmware updates roughly every three months if your router doesn't install them automatically, per Consumer Reports' guidance, and apply security patches as soon as they're offered.
  • Turn off remote management, WPS, and UPnP, three convenience features that widen the attack surface for outside attackers with little day-to-day benefit for most households.
  • A separate guest network keeps visitors and IoT gadgets off the same segment as your laptops and phones, which limits how far a single compromised device can spread.
Safety first

Unplug the unit before any cleaning or filter work.

1

Log into the router's admin panel

Find the admin address, often printed on the router or listed in its manual, commonly something like 192.168.0.1 or 192.168.1.1. This is where every setting below gets changed, so bookmark it if you plan on checking back periodically.

2

Change the admin password and the Wi-Fi password separately

These are two different credentials serving two different jobs, per FTC guidance. Set both to something long and unique, avoiding your name, address, or the router's brand, and store them in a password manager rather than a sticky note on the router itself.

3

Rename the network and confirm WPA3 or WPA2 encryption is active

Swap the default SSID for something generic that doesn't identify the household or router model. In the wireless security settings, confirm WPA3 Personal is selected if available, or WPA2 Personal (AES) if not; avoid anything labeled WEP or plain WPA.

4

Disable remote management, WPS, and UPnP

These usually live under an advanced or administration tab. Turning all three off removes convenience features that see disproportionate attention from automated scanning and attacks, without affecting normal day-to-day use of the network.

5

Set up and enable a guest network

Give it its own unique password, separate from the main network's. Route visitors and any smart-home or IoT devices that only need internet access onto this network instead of the one your personal computers use.

6

Check for firmware updates and turn on automatic updates if offered

Look for a system or firmware tab in the admin panel. If automatic updates aren't available, put a reminder on your calendar to check roughly every three months, and install anything flagged as a security update immediately rather than waiting.

7

Move the router somewhere only household members can reach

A closet shelf or a high spot away from a shared entryway limits who can physically access the reset button, which matters because a factory reset exposes the manufacturer's default login printed on the unit.

8

Do a quarterly device check

Open the router app or admin panel's connected-devices list every few months, alongside your firmware check, and remove anything you don't recognize. Pair this with the password and firmware steps so the whole routine happens on one schedule instead of three.

Quick Facts
Recommended encryptionWPA3 Personal, or WPA2 Personal (AES) as fallback (CISA, FTC)
Firmware check interval without auto-updatesat least every 3 months (Consumer Reports)
Features to disableremote management, WPS, UPnP
Router credentials to change2: admin login and Wi-Fi network password, both separate (FTC)
Common admin panel addresses192.168.0.1 or 192.168.1.1 (varies by router)

How to secure and maintain your wifi router: change the default logins first

A router ships with two separate passwords, the admin login and the Wi-Fi network password, and both need to be changed from their factory defaults before anything else matters.

Shopping for a specific model? See our full wifi router roundup — 10 models compared on the specs that decide it.

It's easy to assume the Wi-Fi password you type into your laptop is the only credential a Wi-Fi router needs. It isn't. The Federal Trade Commission's consumer guidance draws a clear line between the two: the network password lets a device join your Wi-Fi, while the admin password lets someone into the router's settings panel itself, where they could change your DNS, open ports, or lock you out entirely. Leaving the admin side on its factory default is the bigger risk, because those defaults are printed on a sticker on the device and published in manuals that anyone can search.

The FTC's advice is specific: change the default administrative username, password, and network name to something unique, and avoid using your name, address, or the router's brand in any of them. A password manager makes this painless since you never have to remember the string yourself. If you're wondering whether changing your router's default password actually matters, the practical reason is straightforward: default credentials get compiled into public lists that anyone, not just a skilled attacker, can search by device model.

Worth doing at the same time: rename the network itself. CISA notes that a default SSID can hint at the exact router model in use, which narrows down which known vulnerabilities an attacker would try first. A generic name that says nothing about brand, address, or household works better than something identifiable.

Pick the right encryption setting

WPA3 Personal is the current standard; WPA2 Personal with AES is the acceptable fallback on older hardware, and anything labeled WEP or WPA (without a number) should be replaced rather than patched.

Encryption is the setting most people never open because the router usually picks something on its own out of the box. That default isn't always the strongest option available. CISA notes that WPA3 is currently the strongest encryption available, with WPA and WPA2 still in use on older hardware, and recommends WPA2 at a minimum for any network. The FTC frames it the same way, calling WPA3 the newer and best encryption currently available, with WPA2 Personal as the acceptable step down.

If your router's admin panel only offers WEP or plain WPA, that's not a settings problem, it's a hardware age problem. Those older protocols have known weaknesses that a password change can't fix. In that case the more honest fix is a replacement router rather than another tweak to the same box; our wifi router hub is a reasonable starting point if you're comparing what's changed in the years since your current unit shipped.

One practical note: switching encryption standards can briefly disconnect every device on the network, since each one has to reconnect using the new protocol. Plan the change for a moment when nobody's mid-videocall.

Keep firmware current without obsessing over it

Check for firmware updates roughly every three months if your router lacks automatic updates, and install security-labeled updates as soon as they appear rather than waiting for the next scheduled check.

Firmware is a Wi-Fi router's own operating system, and it ages the same way phone software does: patches close holes that researchers and attackers both eventually find. Consumer Reports' guidance suggests checking at least every three months if your router doesn't handle updates automatically, and treating an unpatched router at end of life as a sign it's time to replace rather than keep nursing along. That three-month cadence is a floor, not a ceiling. If a manufacturer flags something as a security update specifically, install it right away instead of waiting for your next quarterly check.

How often should you update router firmware in practice depends on your hardware. Many mesh systems and newer routers install updates automatically in the background, which removes the guesswork entirely, worth confirming in the settings app the first week you own the router. Older standalone routers usually require you to log into the admin page and check manually, and it's the kind of task that's easy to keep meaning to get to.

A firmware check takes a few minutes: log into the admin interface, usually reached at an address like 192.168.0.1 or 192.168.1.1 printed on the router itself, and look for a system or update tab. If the manufacturer's app or site shows the model as discontinued or unsupported, that's the practical end of the update road, and no amount of manual checking closes new vulnerabilities that surface after that point.

Turn off the Wi-Fi router features you don't actually need

Remote management, WPS, and UPnP all trade a small amount of convenience for a meaningfully larger attack surface, and turning off all three is a low-cost way to shrink what an outside attacker can reach.

Routers ship with several features turned on that most households never use on purpose. Remote management lets someone log into the router's settings from outside your home network, which is useful for a tech-savvy relative helping you troubleshoot remotely and useless for everyone else, including attackers scanning the internet for routers that left it open. Disabling it removes one more way in for anyone who isn't already on your home network.

Wi-Fi Protected Setup, the WPS button that lets a new device join with one push instead of typing a password, has a similar problem: it increases the chance an attacker nearby can join without ever knowing your actual password, because the PIN-based version of WPS has documented weaknesses. Universal Plug and Play, or UPnP, automatically opens ports for apps and smart devices that request it, which is convenient until malware on any one device uses that same open door to reach the rest of the network. Security researchers have repeatedly flagged UPnP as a mechanism malware can use to open ports without asking, letting infected devices reach further than they should.

None of these three features are required for normal browsing, streaming, or gaming once initial setup is done. Turning them off in the admin panel closes three doors that see disproportionate attack traffic compared to how often typical households actually use them.

Separate guests and smart devices from your main network

A guest network keeps visiting devices and IoT gadgets off the same segment as your personal laptops and phones, which contains the damage if any single device on it gets compromised.

Most Wi-Fi routers sold in the last several years include a guest network option, and it's frequently left disabled because setting it up feels like an extra step for a rare situation. The better default is the opposite: enable it and give it its own long, unique password, then treat it as the default network for anyone who doesn't live in the house, plus any smart plug, camera, or speaker that only needs internet access and nothing else on your home network.

The reasoning is about containment rather than convenience. Compromised IoT devices have been a recurring source of home botnet activity, and a guest network limits what a compromised device can reach. It can still get to the internet, but it can't quietly probe your laptop or network-attached storage sitting on the main network. That's a meaningfully different outcome than a single flat network where every device can see every other device.

Setting it up is usually a toggle in the same admin panel as everything else here, often under a wireless or guest access tab. Give it a name and password that are different from your main network's, not a close variant of the same phrase.

Physical placement and account hygiene round out the routine

Where the router physically sits and who can reach its reset button matter alongside the software settings, and keeping it somewhere only trusted household members can access closes a gap none of the earlier steps cover.

Everything above assumes an attacker is working remotely, over the internet or from nearby Wi-Fi range. Physical access is a separate risk that's easy to overlook. Anyone who can physically reach the router can factory-reset it and then use the manufacturer's default credentials, printed right on the device, to reconfigure it from scratch. A closet or a high shelf beats a hallway table that guests and repair technicians pass by unsupervised.

Beyond placement, a periodic check of connected devices closes a gap that changing passwords alone doesn't. Most router apps list every device currently connected; scrolling through that list occasionally and removing anything unrecognized is a quick habit that catches a squatter on the network faster than waiting for something to feel slow. It won't replace the password and firmware work above, but it's a useful second check that costs almost nothing.

Worth being honest about the limits here too: none of these steps protect against a vulnerability in the router's firmware that hasn't been patched yet, and no home router setting substitutes for keeping the devices connected to it updated as well. Router security and device security are two different jobs that happen to share the same network.

Frequently asked questions

How do I make my Wi-Fi router more secure?
Change the default admin and Wi-Fi passwords, switch encryption to WPA3 Personal or WPA2 Personal, disable remote management, WPS, and UPnP, and set up a separate guest network for visitors and smart-home devices. These changes cover the password and encryption recommendations CISA and the FTC publish for home routers, plus the additional habits that reduce a router's attack surface day to day.
How often should you update router firmware?
Check roughly every three months if your router doesn't update automatically, per Consumer Reports' guidance, and install any update labeled as a security fix as soon as it's available rather than waiting for the next scheduled check. Many newer routers and mesh systems handle this automatically once enabled in settings.
Should I change my router's default password?
Yes. Default admin credentials are printed on the router itself and published in manuals and compiled lists online, which makes them trivial for anyone to look up by model. The FTC specifically recommends changing both the admin login and the separate Wi-Fi network password from their factory defaults.
What's the difference between the router password and the Wi-Fi password?
The Wi-Fi password is what a phone or laptop uses to join the network. The router admin password is what lets someone log into the router's settings panel to change configuration, including that Wi-Fi password. They're separate credentials and both need changing from their defaults.
Should I hide my Wi-Fi network's SSID?
Hiding the SSID is optional and mostly a minor deterrent rather than real security, since the network is still detectable with basic tools. Renaming it away from anything that identifies your address or router brand matters more than hiding it, since CISA notes a default SSID can hint at known vulnerabilities tied to that router model.
Do I need a guest network if I trust everyone who uses my Wi-Fi router?
A guest network is less about trusting people and more about containing smart-home and IoT devices, which are common targets for compromise. Keeping cameras, plugs, and speakers off the same network as your laptops limits what a compromised device can reach, even in a household where every human user is trusted.

Sources & references

  1. How To Secure Your Home Wi-Fi Network — Federal Trade Commission (FTC), Consumer Advice
  2. Securing Wireless Networks — Cybersecurity and Infrastructure Security Agency (CISA)
  3. How to Boost Your Router Security — Consumer Reports
BB
Buyer Reports Editorial Updated 2026-08-08 · Research-based, no sponsored placements