Change default router administration credentials, use WPA3 or WPA2, update firmware and separate guest or low-trust devices when supported.
I need to secure a home network
Secure the router’s administrative control plane, choose modern Wi-Fi protection and isolate less-trusted devices while preserving a recovery path.
The safest way to start
Change default router administration credentials, use WPA3 or WPA2, update firmware and separate guest or low-trust devices when supported.
Save supported configuration backups and record ISP details before changing credentials, firmware or network names.
Do not expose remote administration, reuse the Wi-Fi password for router admin access or leave obsolete security modes enabled.
Stop if the router is managed by an ISP or organization and the change could disable voice service, authentication, remote support or required business connectivity.
Router administration uses a unique non-default password.
Quick checks before changing anything
Use these checks to narrow the problem and avoid applying an unrelated fix.
Identify the router owner and model
Confirm whether the router belongs to you, an ISP, landlord or employer and record the exact model before changing settings.
Check administrative access
Determine whether the router still uses a default administrator password or exposes management from the internet.
Review Wi-Fi security mode
Look for WPA3-Personal or WPA2-AES. Legacy WEP, open networks and mixed modes with weak compatibility options require review.
Safe first actions
Mark actions as you complete them. Progress is stored only in this browser.
Step-by-step route
Continue only when the result of the current step supports the next one.
- 1
Secure administration
Disable remote administration unless required, update the admin password and review authorized administrators.
Expected resultInternet users cannot reach a default or exposed control panel. - 2
Use modern Wi-Fi protection
Select WPA3 when all critical devices support it, otherwise WPA2-AES, and set a strong unique Wi-Fi passphrase.
Expected resultWireless traffic is protected without locking out necessary devices. - 3
Update firmware and services
Install supported firmware, disable unused features such as WPS or UPnP when not needed, and review DNS settings.
Expected resultKnown vulnerabilities and unnecessary exposure are reduced. - 4
Segment guests and smart devices
Use a guest network or isolated segment for visitors and less-trusted devices when the router supports it.
Expected resultCompromise of a guest or smart device has less access to personal computers and storage.
Stop and escalate when
- Stop if the router is managed by an ISP or organization and the change could disable voice service, authentication, remote support or required business connectivity.
How to know the problem is resolved
- Router administration uses a unique non-default password.
- Wi-Fi uses WPA3 or WPA2-AES with no open or WEP network.
- Firmware, guest access and recovery information have been reviewed and documented.
Recommended learning route
Open these lessons in order when you need more detail or want to prevent the issue from returning.
Secure the router administrator account
Change default credentials and limit who can manage settings.
Wi-Fi & Networking · Secure and Optimize the NetworkChoose WPA2 or WPA3 correctly
Avoid obsolete encryption and use a strong unique Wi-Fi password.
Wi-Fi & Networking · Secure and Optimize the NetworkUse a guest network
Separate visitors and less-trusted devices from your main network.
Wi-Fi & Networking · Secure and Optimize the NetworkConfigure network names and passwords
Use clear SSIDs and strong modern security without exposing personal information.
Wi-Fi & Networking · Wi-Fi Signal and Router SetupTipsMake tools and guides
Continue with a connected problem
FAQ
Should the router admin password and Wi-Fi password be the same?
No. They protect different functions. A guest may need Wi-Fi access but should never gain permission to change router firmware, DNS or security settings.
Is hiding the SSID a strong security control?
No. The network name can still be discovered in wireless management traffic. Use modern encryption, a strong passphrase and secure router administration instead.