Home Wi-Fi Router Security Checklist: 10 Settings to Fix Tonight

Your router is the front door for every device in the house, and most ship with that door on the latch. Ten settings ranked by impact, then a 20-minute pass through the admin page to set them all.

A home Wi-Fi router on a shelf beside a laptop in a calm blue-lit room
AI-generated illustration

The checklist, most important first

1. Change the admin password

The sticker password (or "admin/admin") is printed in every manual online. Anyone on your Wi-Fi, or malware on a laptop, can log in and rewrite your settings. CISA and the FTC both put this first.

  • Where: Administration or System, then Password; change the username too if the router allows it
  • Use: a generated 16-plus character password saved in your password manager

2. Use WPA3, or WPA2 with a long passphrase

Encryption stops a neighbour or a parked car reading your traffic or joining your network. The NSA's guidance: WPA3-Personal where every device supports it, WPA2/WPA3 mixed mode where not, and a passphrase of at least 20 characters.

  • Where: Wireless, then Security; pick WPA3-Personal or WPA2/WPA3-Personal, AES only
  • Never: WEP, original WPA, TKIP, or an open network

3. Update the firmware and turn on auto-update

Router bugs are patched constantly, and unpatched routers are what botnets are built from. Most current routers can install updates on their own overnight; Netgear and TP-Link both document the switch.

  • Where: Administration, Firmware or Router Update; enable automatic updates
  • Habit: if there is no auto option, put a quarterly reminder in your calendar

4. Turn off WPS

Wi-Fi Protected Setup lets devices join by button press or an eight-digit PIN. The PIN scheme is broken by design: CISA warned in 2012 that it can be brute-forced in hours, handing an attacker your Wi-Fi password. Nothing in your house needs it.

  • Where: Wireless, then WPS; set it to Off or Disabled
  • Instead: type the passphrase once per device, or share it with a QR code from your phone

5. Turn off remote management

Remote management exposes the router's login page to the whole internet so you can tweak settings from anywhere. In practice it exposes it to scanners hunting weak passwords and unpatched bugs. The FTC says turn it off.

  • Where: Administration or Advanced, then Remote Management, Web Access from WAN, or similar
  • Need it anyway? Use the maker's phone app, which connects through its cloud rather than an open port

6. Turn off UPnP

Universal Plug and Play lets any device on your network ask the router to open a hole in the firewall, with no password. It is why a console "just works" online, and why malware on one device can quietly expose another. Canada's Cyber Centre recommends disabling it on home routers.

  • Where: Advanced, NAT Forwarding or WAN, then UPnP
  • Trade-off: a console may report "strict NAT"; add a manual port-forward rule for that one device

7. Turn on a guest network for visitors

A guest network gives visitors internet without your main password or a view of your printer, backup drive and laptops. Turn on client isolation (sometimes "AP isolation") so guest devices cannot see each other.

  • Where: Wireless, then Guest Network; give it its own name and password
  • Rotate: change the guest password whenever a house guest or contractor leaves

8. Put smart-home devices on their own network

Smart plugs, bulbs, cameras and TVs get security updates rarely, then not at all. Move them to the guest network (or an IoT network if your router offers one) so a compromised gadget cannot reach the devices holding your files.

  • Where: the same Guest Network page; some mesh systems (eero, Orbi, Deco) offer a dedicated IoT network
  • Watch-out: casting to a TV on the other network may need isolation loosened; test as you go

9. Rename the network, and keep it visible

The default name ("NETGEAR47", "TP-Link_3C2A") tells a passer-by your router model and, for some brands, hints at the default password. Change it to something bland, and do not hide it: the NSA advises against hidden networks because your devices then broadcast the name everywhere they go.

  • Where: Wireless, then Network Name (SSID)
  • Avoid: your surname, flat number or anything that identifies the house

10. Retire end-of-life routers

When a maker stops publishing updates, every bug found afterward stays open forever. In May 2025 the FBI warned that criminals were mass-infecting end-of-life routers to sell as proxy nodes. Check your model on the maker's support page; if it is unsupported, replace it.

  • Cost: a solid WPA3 router runs roughly $80 to $150 in September 2026
  • ISP box? the NSA suggests your own router behind the ISP modem; at minimum change the ISP box's admin password

What doesn't matter much

  • Hiding the network name. Scanners still see it, and your phone leaks it in cafés.
  • MAC address filtering. Addresses are copied in seconds and phones randomise theirs anyway.
  • Static IP addresses or disabling DHCP. Inconvenience for you, no obstacle to anyone else.
  • Turning the router off at night. Harmless, but the threats above do not keep office hours.

The 20-minute pass

  1. Open the admin page. The address is on the sticker (often 192.168.0.1 or 192.168.1.1) or in the maker's app.
  2. Change the admin password and save it to your password manager first.
  3. Fix Wireless Security. WPA3-Personal or WPA2/WPA3, a new 20-plus character passphrase, and a fresh network name. Every device will reconnect afterwards.
  4. Check for firmware and turn on automatic updates.
  5. Switch off WPS, remote management and UPnP. Three toggles, usually under Advanced.
  6. Turn on the guest network with isolation and move smart-home devices over one at a time.
  7. Log out of the admin page. The FTC recommends it; it stops a stray browser tab being used against you.
Tip: Before you start, photograph the sticker and note the current settings. You will thank yourself when a device refuses to reconnect or the router needs a factory reset.
Warning: If your model is on the FBI's end-of-life list, or the maker's site shows no firmware newer than a few years, no setting on this page saves it. Replace it.

Quick answers

Should I use WPA2 or WPA3 on my home router?

WPA3-Personal if every device supports it, otherwise the WPA2/WPA3 mixed mode most routers offer. Either is fine with a passphrase of 20 characters or more. Never use WEP, WPA (the original) or an open network.

Is it safe to leave WPS turned on?

No. The WPS PIN method has a design flaw, documented by CISA in 2012, that lets an attacker within range guess the PIN in hours and pull your Wi-Fi password. Turn WPS off in the wireless settings and connect new devices by typing the passphrase.

Do I need a separate network for smart home devices?

It is the most useful upgrade after the basics. Smart plugs, cameras and TVs get patched rarely; putting them on a guest or IoT network with device isolation means one compromised gadget cannot reach your laptop, phone or backups.