Router credentials guard everything behind them — one kept default like admin/password123 exposes laptop, phone and bank logins at once. Here is what to change, in order: admin password, Wi-Fi passphrase, guest network. This is the practical setup: strong Wi-Fi and router passwords in 15 minutes, once.
Part of the password generator guide. Generate both secrets in the password generator; bulk tokens via random string tool. Concepts in creation steps.
Two secrets, two jobs (stop confusing them)
- Router admin password: guards settings (DNS, firmware, port forwarding). Change from default immediately — botnets scan for admin/admin daily. 20+ random characters, stored in manager, never shared. If the router was ever secondhand, factory-reset before configuring (previous owners keep access otherwise).
- Wi-Fi passphrase (WPA2/WPA3 PSK): guards network join. 20+ characters or 5-word passphrase; WPA3 where hardware supports it, WPA2-AES minimum — never WEP or open (both offer zero real protection).
- Different secrets, always: admin ≠ Wi-Fi. Guests get Wi-Fi only, via QR or dictated passphrase — never admin access, never the same string.
Setup walkthrough (15 minutes, once)
- Connect by cable, log in with defaults (sticker values), and check for firmware updates first — unpatched routers fall regardless of password strength.
- Set admin password: generate 20+ random characters, save in manager. Disable remote/WAN administration unless you truly administer remotely (almost nobody should).
- Set Wi-Fi passphrase: generate a 5-word passphrase for dictation ease or 20-char random for max strength; WPA2-AES minimum, WPA3 preferred.
- Create the guest network: separate SSID (“Home-Guest”), isolated from main devices, with its own passphrase. Share via QR on the fridge — visitors stop asking, and IoT gadgets live here too, quarantined from laptops.
- Record + verify: admin in manager, Wi-Fi on the fridge QR, then test: guest device reaches internet but not your laptop's shares; admin panel rejects old defaults.
IoT gadgets and guests (the forgotten attack surface)
Smart bulbs, cameras and plugs ship with default credentials and rare updates — isolate all of them on the guest network, where compromise reaches the internet but not your laptop or NAS. Change each gadget's default password where possible (many allow it in-app); where impossible, network isolation is the entire defense. Guests: QR code, never dictation of the main passphrase — rotating the guest passphrase yearly costs nothing and bounds exposure from every visitor's compromised phone. Moving house? Factory-reset the router before selling or returning it — your Wi-Fi history and ISP credentials live in its config backup.
Secondhand routers and moving house (reset discipline)
Routers carry history: previous owner's ISP credentials, port forwards, DNS overrides and saved Wi-Fi PSKs persist through ownership changes. Buying used? Factory-reset before first configuration, flash latest firmware, then set fresh admin + PSK — treat all prior settings as hostile. Selling or returning ISP hardware? Factory-reset and verify: log back in with defaults to confirm the wipe, remove the device from ISP/bank “trusted devices” lists, and rotate any password ever typed on its admin pages from another device. Movers: export nothing — photograph settings if needed, rebuild clean at the new address (new SSID, new secrets), and retire the old PSK everywhere it was shared. Fifteen minutes of reset discipline closes an attack surface most households never think about.
General information only, not security advice. Generate offline, store in a manager, enable MFA on email/bank. If you lose your master password it cannot be recovered by us.