Five Minute Security
Five-Minute Fixes

Five Router Settings Worth Checking Tonight

Five Router Settings Worth Checking Tonight
This article explains how to secure your home network by checking five essential router settings in just five minutes. Written by a former threat analyst, it covers changing the default administrator password, verifying WPA2 or WPA3 encryption, disabling remote management, turning off WPS, and reviewing UPnP. The guide offers a simple, actionable baseline to prevent unauthorized network access and protect every connected device.

The Conversation That Prompted This Post

"Dave, the Wi-Fi's slow again."

That's Emily, usually when she's trying to grade papers and stream something at the same time. The Wi-Fi's a regular topic in our house—right up there with what's for dinner and whether Miles needs a bath.

For a long time, I treated the router like a toaster. Plug it in, set it up once, forget about it until something breaks.

That's what most of us do. The router sits in the corner, blinking lights, doing its job. A recent survey found that more than 86% of households have never changed their router's administrator password . That's essentially locking your front door with the key still in it. Most people treat their router like an appliance you set up once and then forget about until it breaks .

But here's the thing about routers—they're the front door to your entire digital life. Every device in your house connects through them. Every password you enter, every website you visit, every smart device you control.

If someone gets into your router, they get into everything.

The good news is that securing a router isn't complex. It takes about five minutes to check the settings that matter most. That's my kind of security fix.


The Settings I Check First

1. The Administrator Password

This is the one that keeps me up at night.

Your router has two passwords: the Wi-Fi password (the one you type to connect) and the administrator password (the one you use to change settings). Most people change the Wi-Fi password and completely forget about the administrator one.

Here's the problem: routers ship with default admin credentials—often something like "admin/admin" or "admin/password." That information is published online. Anyone with access to your network can look up the default credentials for your router model and take control .

What to do tonight:

  1. Log into your router (usually by typing 192.168.1.1 or 192.168.0.1 into a browser—check the sticker on your router for the exact address)

  2. Look for "Administration," "Management," or "System"

  3. Change the default username and password to something strong and unique

This is the single most important change you can make. A 2022 report from CISA found that unpatched vulnerabilities in network devices, including routers using default credentials, are a frequent vector for attacks against home users . Attackers don't need to be clever—they just need the default password.

Close-up of an adult logging into a router administration settings page on a laptop at a home desk.

2. The Encryption Standard

This one's about the Wi-Fi password you use to connect devices.

WPA2 and WPA3 are the secure encryption standards you want. WEP and WPA are old and easily cracked . If your router is still using an old standard, it's like having a lock that can be picked with a paperclip.

Check your Wi-Fi security settings. If the encryption type isn't WPA2-PSK (AES) or WPA3, change it . WPA3 is the latest and most secure, but some older devices might not support it. If that's the case, stick with WPA2—it's still secure enough for home use .

3. Remote Administration

Most routers allow you to access their settings from outside your home network. This feature is called "Remote Management," "Web Access from WAN," or something similar.

Here's the simple rule: unless you have a specific reason to access your router from outside your home, turn it off .

Disabling remote management prevents the router management page from being exposed directly to the internet . If a hacker can't reach the page, they can't try to brute force your admin password. If you do need it, make sure remote access is locked to a specific IP address .

4. Wi-Fi Protected Setup (WPS)

WPS is a feature designed to make connecting devices to Wi-Fi easier. You push a button on the router, and a device connects without entering the password.

The problem: the PIN method used by WPS has a known vulnerability that can be brute-forced. Even with a strong Wi-Fi password, an attacker could potentially guess the WPS PIN and gain access to your network in a few hours .

Unless you need it for a specific device that only supports WPS connections, disable it. The convenience isn't worth the risk.

5. Universal Plug and Play (UPnP)

UPnP is designed to let devices automatically discover each other and open ports as needed. It's convenient for gaming consoles, streaming devices, and some smart home equipment.

Why I'm skeptical: UPnP doesn't require authentication. Any device on your network can request port forwarding, potentially creating security holes. The University of British Columbia's security guidance recommends disabling UPnP unless you have a specific need for it .

Try disabling UPnP and see what breaks. If your devices still work fine, leave it off. If something stops working (like online gaming), weigh the convenience against the security risk.


One More Thought: Your Network Name (SSID)

I've seen advice about hiding your network name (SSID) to avoid detection. I used to be skeptical of this for the same reason many security professionals are—it's trivial for anyone with basic tools to detect a hidden network, and your own devices end up broadcasting requests for it constantly, which can actually make you easier to track .

But this is one of those cases where the risk is simpler than the technical debate. If you don't change the default SSID, it often reveals what kind of router you have. That makes it easier for someone to look up known vulnerabilities for that specific model . Changing the network name to something generic is a small step that provides a minor layer of privacy.


The Five-Minute Action Plan

If you only have five minutes, here's what to check in order:

Priority 1: Change the administrator password. This is the most critical fix and takes under two minutes .

Priority 2: Verify your encryption is set to WPA2 or WPA3. Check the Wi-Fi security settings .

Priority 3: Disable remote administration. Look for a setting about WAN access or remote management .

Priority 4: Disable WPS. Find it in the wireless settings .

Priority 5: If you have time, look for UPnP and consider turning it off .

A smartphone and laptop resting on a clean home desk displaying Wi-Fi security encryption settings.

Next Week: I'll walk through the school Chromebook question I've been asked more than any other—how to manage a school-issued device without giving away your child's privacy. It's one of those topics where the answer is more practical than technical.


Dave C. — Five minutes now beats five hours later.

Revised · 2026-09-09 11:20
Margin Notes

No notes on this sheet yet.

Add a Note
© 2026 The Five Minute Security. All rights reserved. drawn by hand