IP Location.net

IP Address, Network, Cybersecurity

Is Your Router Secure? Everything You Need to Know About Home Router Security

Your router is the front door to your home network. Every computer, phone, smart TV, doorbell camera, and voice assistant in your house sends its traffic through it. If an attacker gets into your router, they can see where your devices go online, send you to fake websites, add your devices to a botnet, or reach devices on your network that were never meant to face the internet.

Most home routers are left the way they came out of the box: default admin password, old firmware, and settings chosen for easy setup rather than security. The good news is that fixing this takes about 15 minutes, and you don't need to be a network expert.

This guide explains how routers work, what makes them vulnerable, the default login details for the most popular brands, and how to plan the IP addresses on your home network.

What Your Router Actually Does

Most home "routers" are really several devices in one box:

  • Router: moves traffic between your home network and the internet.
  • NAT (Network Address Translation): lets all your devices share the single public IP address your internet provider gives you. Each device gets a private IP address inside your home.
  • DHCP server: hands out those private IP addresses to devices automatically.
  • Wi-Fi access point: creates your wireless network.
  • Firewall: blocks unwanted connections from the internet.
  • Modem (sometimes): connects to your provider's cable, fiber, or DSL line. Provider-supplied "gateways" usually combine the modem and router in one box.

You can see the public IP address your router presents to the internet with our What Is My IP tool. Websites and online services see that address, not the private addresses of your individual devices.

Why Routers Get Hacked

Attackers rarely target a specific home. They run automated scans across the internet, looking for any router with a known weakness. The most common ones:

  1. Default or weak admin passwords. Default login details for every router model are published online (including below). If you never changed yours, anyone who reaches your router's login page can get in.
  2. Outdated firmware. Router makers regularly fix security flaws. A router that hasn't been updated in years may have flaws that are publicly documented and easy to exploit.
  3. Remote management turned on. This makes the router's admin page reachable from the internet, not just from inside your home.
  4. WPS (Wi-Fi Protected Setup). The PIN method of WPS has a well-known design flaw that lets attackers guess it in hours.
  5. UPnP (Universal Plug and Play). It lets apps and devices open ports on your router automatically. That's convenient for gaming consoles, but malware can use it too.
  6. Weak Wi-Fi encryption. Old standards like WEP can be cracked in minutes.
  7. End-of-life hardware. Once a manufacturer stops releasing updates for a model, new vulnerabilities will never be fixed.

A compromised router is dangerous because it's hard to notice. Your internet keeps working while traffic is quietly redirected, monitored, or used to attack others.

Wi-Fi Encryption: WEP vs WPA vs WPA2 vs WPA3

Wi-Fi encryption scrambles the data sent between your devices and the router, so nearby people can't read it or join your network without the password.

Standard Year Security level Recommendation
WEP 1999 Broken. Can be cracked in minutes. Never use
WPA (TKIP) 2003 Weak and outdated. Avoid
WPA2-Personal (AES/CCMP) 2004 Good if the password is strong. Acceptable minimum
WPA3-Personal (SAE) 2018 Strongest; resists offline password guessing. Use this when available
WPA2/WPA3 mixed (“transition”) mode — Works with older devices; WPA3 devices get the stronger protection. Good compromise

What to choose:

  • Pick WPA3-Personal if all your devices support it.
  • Use WPA2/WPA3 mixed mode if some older devices, like printers or smart plugs, can't connect with WPA3.
  • If you're stuck on WPA2, make sure it's set to AES, not TKIP or "TKIP+AES".
  • Use a Wi-Fi password of at least 12 to 16 characters. A short random phrase such as seattle-pier-66-is-great is strong and easy to type.

Encryption only protects the connection between your devices and the router. Once your traffic reaches the internet, you're relying on HTTPS and, if you use one, a VPN.

Default Router Login Details by Brand

To change your router's settings, open a web browser on a device connected to your network and go to the router's login address. The lists below show the most common defaults.

Important: Details vary by model, firmware version and region. Most routers made in the last few years no longer ship with a shared default password. Instead, they print a unique password on the label or make you create one during setup, often through a mobile app. Always check the sticker on the bottom or back of your router first.

Retail router brands

Brand Login address Default username Default password Notes
TP-Link tplinkwifi.net, 192.168.0.1, or 192.168.1.1 admin admin Newer models ask you to create a password on first login. Deco mesh systems are set up in the Deco app.
Netgear routerlogin.net or 192.168.1.1 admin password Newer models ask for a password during setup. Orbi and Nighthawk can be managed in their apps.
Linksys myrouter.local or 192.168.1.1 admin (or blank) admin Velop mesh systems are set up in the Linksys app.
ASUS router.asus.com, 192.168.50.1, or 192.168.1.1 admin admin Current models make you set new login details during first setup.
D-Link dlinkrouter.local or 192.168.0.1 admin (blank) Many models ship with no password at all. Set one immediately.
Belkin router.belkin or 192.168.2.1 (none) (blank) Older models have no admin password by default.
Ubiquiti (UniFi) Set up in the UniFi app or at 192.168.1.1 (created during setup) (created during setup) Older EdgeRouter models used ubnt / ubnt.
Huawei 192.168.3.1, 192.168.8.1 (mobile routers), or 192.168.100.1 admin admin, or printed on label Varies widely by model and internet provider.
ZTE 192.168.1.1 or 192.168.0.1 admin (or user) admin (or user), or printed on label Provider-supplied units often use custom login details.
Arris / Motorola 192.168.0.1 (gateways) or 192.168.100.1 (modem status page) admin password, or printed on label The modem status page usually does not need a login.

Internet provider routers (US)

Provider Login address Login details Notes
Xfinity (Comcast) 10.0.0.1 admin / password (you are required to change it on first login) The Xfinity app is the main way to manage it.
AT&T 192.168.1.254 “Device Access Code” printed on the label The Wi-Fi password is also on the label.
Spectrum 192.168.1.1 Printed on the label Most settings are managed in the My Spectrum app.
Verizon Fios 192.168.1.1 or mynetworksettings.com admin / password printed on the label Newer routers can be managed in the My Fios app.

Can't log in? Someone may have changed the password. Hold the reset button (usually a small pinhole) for 10 to 30 seconds while the router is on. This restores factory settings, including the default login. You'll need to set up your Wi-Fi network and any custom settings again.

Router Security Checklist: 12 Steps to Lock It Down

Work through this list once, then check it again every few months.

Essentials (do these today)

  1. Change the admin password. This is the password for the router's settings page, which is separate from the Wi-Fi password. Use a long, unique password and store it in a password manager.
  2. Update the firmware. Look for "Firmware Update" or "Administration" in the settings and turn on automatic updates if offered.
  3. Use WPA3 or WPA2-AES encryption with a strong Wi-Fi password.
  4. Turn off remote management, which may be called "Remote Access", "Web Access from WAN" or "Cloud Management", unless you truly need it.
  5. Turn off WPS. Connecting by typing the Wi-Fi password is safer.

Recommended

  1. Turn off UPnP unless a gaming console or app needs it. If you need an open port, set up port forwarding for that one device instead.
  2. Change the default network name (SSID). Names like "NETGEAR42" or "TP-Link_5G" reveal your router brand. Avoid putting your name or address in it.
  3. Turn on the guest network for visitors, and turn off guest access to your main network.
  4. Put smart home devices on a separate network. Cameras, plugs and TVs often have weak security. Keeping them on the guest network or their own network (VLAN) keeps a compromised gadget away from your laptop and phone.
  5. Check which devices are connected. Look at the router's "Connected Devices" or "DHCP Clients" list and investigate anything you don't recognize.

Advanced

  1. Use a trusted public DNS service such as Cloudflare (1.1.1.1), Quad9 (9.9.9.9) or Google (8.8.8.8). Quad9 and Cloudflare's 1.1.1.2 also block known malicious sites.
  2. Replace routers that no longer get updates. If the manufacturer has stopped releasing firmware for your model, it's time to upgrade. Current Wi-Fi 6 and Wi-Fi 7 routers support WPA3 and receive security fixes.

Signs Your Router May Be Compromised

  • Your router's admin password no longer works, and you didn't change it.
  • The DNS server settings have changed to addresses you don't recognize.
  • You're redirected to strange websites, or see certificate warnings on sites you use often.
  • There are unknown devices in the connected-devices list.
  • New port-forwarding rules appeared that you didn't create.
  • Your internet is unusually slow, or the router's activity lights flash constantly while nothing is in use.

If you suspect a problem: factory-reset the router, install the latest firmware, set a new admin password and Wi-Fi password, and work through the checklist above. Then change the passwords for your important online accounts, like email and banking, from a device you trust.

Planning IP Addresses for Your Home Network

Every device on your home network needs a private IP address. Your router assigns these automatically, but understanding how it works helps you troubleshoot problems, set up port forwarding, and avoid conflicts.

Private IP address ranges

Three address ranges are reserved for private networks (defined in RFC 1918). They're never used on the public internet, so your router can use them freely inside your home:

  • 10.0.0.0 to 10.255.255.255 (10.0.0.0/8): about 16.7 million addresses. Xfinity routers use 10.0.0.1.
  • 172.16.0.0 to 172.31.255.255 (172.16.0.0/12): about 1 million addresses. Rarely used at home.
  • 192.168.0.0 to 192.168.255.255 (192.168.0.0/16): about 65,000 addresses. Most routers default to 192.168.0.1 or 192.168.1.1.

A typical home network uses a single /24 subnet, which provides 254 usable addresses, for example 192.168.1.1 to 192.168.1.254. That's more than enough for most households.

Addresses not to use:

  • Public IP ranges. Making up a range like 50.0.0.0 will break access to real websites that use those addresses.
  • 100.64.0.0/10, which is reserved for providers' shared addressing (CGNAT).
  • 169.254.x.x. If a device shows this address, it failed to get one from your router. It's a symptom of a problem, not a setting to choose.

Tip: avoid the most common subnets

192.168.0.x and 192.168.1.x are the defaults on most routers. They work fine, but if you use a work VPN, the VPN may use the same range, and the conflict can stop you reaching work or home devices. Choosing a less common subnet prevents this, for example:

  • 192.168.37.0/24 (router at 192.168.37.1)
  • 10.20.30.0/24 (router at 10.20.30.1)

You can change this in your router's LAN or DHCP settings.

An example home network plan

  • 192.168.37.1: the router (fixed).
  • 192.168.37.2 to 192.168.37.49: printers, NAS, home server, cameras and access points, each given a fixed address with a DHCP reservation.
  • 192.168.37.50 to 192.168.37.200: phones, laptops, TVs and guest devices, assigned automatically by the router (the DHCP pool).
  • 192.168.37.201 to 192.168.37.254: spare for future use.
  • 192.168.38.0/24: a separate guest or smart-home network, assigned automatically.

DHCP reservation vs static IP: to give a device such as a printer the same address every time, create a DHCP reservation on the router. It links the device's MAC address to a chosen IP address. This is easier and less error-prone than typing a static IP into the device itself, because everything is managed in one place.

What about IPv6?

Many internet providers now support IPv6, the newer address system with a practically unlimited number of addresses. With IPv6, your devices may get globally unique addresses instead of relying on NAT. That's not a security risk as long as your router's IPv6 firewall is turned on, which it is by default on modern routers. Check that it's enabled, and don't create IPv6 "allow all" rules.

Port forwarding and CGNAT

Port forwarding lets someone on the internet reach a specific device at home, such as a game server or a security camera. Every forwarded port is a way in, so:

  • Forward only the ports you need, and only to a reserved IP address.
  • Remove rules you no longer use.
  • Consider a VPN (such as WireGuard or Tailscale) for remote access instead of exposing devices directly.

If port forwarding doesn't work at all, your provider may be using CGNAT. Compare the WAN IP address shown in your router with the address shown by our IP lookup tool. If they're different, or the router's WAN address starts with 100.64 to 100.127, you're behind CGNAT. Ask your provider for a public IP address, or use IPv6.

FAQ

Frequently Asked Questions

01Is my router secure if I've never changed anything?

Probably not completely. Newer routers with unique label passwords and automatic updates are reasonably safe out of the box. Older routers with default passwords and old firmware are easy targets.

02How often should I update my router's firmware?

Turn on automatic updates if your router has them. Otherwise, check every few months.

03Should I hide my Wi-Fi network name (SSID)?

It isn't worth it. Hidden networks are still easy to detect with free tools, and hiding the name can cause connection problems. A strong password and WPA3 matter far more.

04Is MAC address filtering worth using?

Not as a security measure. MAC addresses are easy to copy, and many phones now use a random MAC address for each network.

05How long does a router last?

Most routers get security updates for about 3 to 5 years after release. When updates stop, it's time to replace it.

06Can my internet provider see my router settings?

If you use a router supplied by your provider, it can usually manage the device remotely. If that concerns you, you can use your own router and put the provider's device in bridge mode.

The Bottom Line

Router security comes down to a few habits: change the default password, keep the firmware updated, use WPA3 or WPA2-AES, and turn off features you don't use, like WPS, UPnP and remote management. Add a separate network for guests and smart devices and a sensible IP address plan, and your home network will be much harder to attack than most.

Share this Post

Comments

Comments are available to signed-in users and are moderated to keep the discussion useful and respectful. Spam, automated submissions, and low-value promotional comments are removed. Outbound links may be approved when they are relevant and genuinely helpful to readers, but they are displayed as plain text rather than clickable hyperlinks.

No comments have been published yet.

Please sign in to submit a comment.