Your home router is the gateway to every device on your network — computers, phones, tablets, smart TVs, cameras, doorbells, and thermostats. A poorly configured router exposes all of them. These eight steps address the most common vulnerabilities, covering guidance from CISA and the FTC.
8 Steps to Secure Your Router
1. Change the Default Admin Password (Critical)
Default credentials (admin/admin, admin/password) are publicly documented for every router model and are the first thing attackers try. Log into your router admin panel (usually at 192.168.1.1 or 192.168.0.1 in your browser), go to Administration or Security, and set a strong unique password. Store it in your password manager.
2. Update Router Firmware (Critical)
Router manufacturers release security patches for discovered vulnerabilities. Check your admin panel for a Firmware Update option under Administration or Advanced Settings. Enable automatic updates if available. Many routers run unpatched for years because owners do not know this setting exists.
3. Use WPA3 Encryption — or WPA2 Minimum (Critical)
Check Wireless → Security settings. Select WPA3 if available, or WPA2-AES at minimum. Never use WEP or original WPA — these are cryptographically broken and can be cracked in minutes with publicly available tools.
4. Change the Default Wi-Fi Name (SSID)
The default name (e.g. “NETGEAR72”) reveals your exact router model, allowing attackers to look up known vulnerabilities for that specific device. Use a custom name that does not identify you, your address, or your router brand.
5. Create a Separate Guest Network for IoT Devices (High)
Put smart home devices — TVs, cameras, thermostats, smart bulbs — on an isolated Guest network, separated from your computers and phones. If a smart device is compromised, network isolation prevents the attacker from pivoting to your laptop or phone.
6. Disable WPS (High)
Wi-Fi Protected Setup has well-documented vulnerabilities that allow an attacker within Wi-Fi range to crack your network password in hours. Disable it in Wireless settings. It provides marginal convenience at significant security cost.
7. Disable Remote Management (High)
Remote management allows your router admin panel to be accessed from the internet. Unless you specifically need this, disable it. It prevents attackers from attempting to access your router from anywhere in the world.
8. Enable the Built-in Firewall
Most routers have a built-in SPI (Stateful Packet Inspection) firewall — verify it is enabled in Security settings. This blocks unsolicited inbound connections from the internet.