Wi-Fi router security: a plain-English checklist for your home network

Malware / security. Updated 2026-09-13. About 5 minutes to read.

Change the router's admin password, update its firmware, set Wi-Fi security to WPA3 or WPA2, and turn off WPS and remote management.

Your router is the front door to every phone, laptop, camera and smart speaker in your home, and most people never change a single setting after the installer leaves. Criminals know that. Australia's Signals Directorate says home and small office routers are targeted for recruitment into botnets, and there are about 8.3 million residential internet connections in Australia that rely on them.

In May 2025 the FBI warned that criminals were infecting old, unsupported routers that had remote administration turned on, then renting them out as proxies to hide other crimes. The good news is that a handful of settings, done in the order below, closes most of those gaps in about 30 minutes.

Before you start: get into your router's settings

  1. Find the brand and model on the label underneath the router. The label usually also shows the default Wi-Fi name, Wi-Fi password and admin login.
  2. Check whether your internet provider manages the router. Provider routers often use an app and may hide some settings.
  3. Open the router's app, or type its address into a browser while connected to your network. Common addresses are 192.168.0.1 and 192.168.1.1, and the label or manual lists yours.
  4. Sign in with the admin details from the label. If they were changed and nobody remembers them, a factory reset restores the defaults, but you will need to set up the internet connection again.

The six changes that matter most

  1. Change the admin password, which is the one used to log in to the router's settings. Make it different from your Wi-Fi password. The FBI recommends a unique, random password of at least 16 characters.
  2. Update the firmware from the router's settings or app, and turn on automatic updates if the option exists.
  3. Set Wi-Fi security to WPA3. If older devices cannot connect, use WPA3 transition mode, and if that is not available, WPA2, sometimes shown as WPA2-Personal or WPA2-PSK. Never use WEP, WPA or an open network.
  4. Give the network a name that does not include your surname, address or router brand, and set a long Wi-Fi passphrase.
  5. Turn off WPS, the push-button or PIN pairing feature. The ACSC notes the PIN can be brute forced, and you do not need it.
  6. Turn off remote management, including web access from the internet, Telnet, SSH and SNMP. The ACSC says remote management is one of the most common ways routers are compromised.

Hiding your network name and filtering by device address are not security. Both are easy to get around and mostly create problems for your own devices. Spend the time on the six steps above instead.

Switch off features you do not use

  • UPnP lets devices open connections through your router automatically. The ACSC says malware has used it to compromise routers. Turn it off unless a games console or smart device stops working, then decide whether you need that device's online feature.
  • Port forwarding sends outside internet traffic to a device inside your home. Most households do not need any rules here, so delete ones you did not create.
  • FTP and USB file sharing on the router expose whatever drive is plugged in. Turn them off unless you use them.
  • Cloud or remote access features in the router's app are convenient but add an account that can be phished. Protect it with two-factor authentication or turn it off.

Put guests and smart devices on a separate network

Most routers can run a guest network with its own name and password. The ACSC recommends it for visitors and untrusted devices, because it keeps them apart from your laptops and phones.

Cheap smart plugs, cameras and TVs are the devices most likely to have weak security, so many households put them on the guest network too. The trade-off is that casting from your phone to a TV, or controlling some devices locally, only works when both are on the same network. Test each device after you move it.

When to replace your router

  • The manufacturer no longer releases firmware updates, or the model is listed as end of life.
  • The FBI says routers from 2010 or earlier are unlikely to still receive updates.
  • It cannot do at least WPA2. The ACSC suggests replacing a router that does not support WPA2.
  • Your provider supplied it many years ago. Ask the provider for a current model, which is often free.

Signs your router has been compromised, and what to do

The FBI lists overheating, connection problems and settings you do not recognise as common signs of router malware. Other clues are your browser landing on strange pages, or unknown devices in the connected devices list.

  1. Unplug the router from the internet connection.
  2. Hold the reset button, usually for around 10 seconds, until the lights change, to restore factory settings.
  3. Update the firmware before reconnecting your devices.
  4. Set a new admin password, Wi-Fi passphrase and security mode, and turn WPS and remote management off again.
  5. Change the passwords for your email and banking from a device you trust, in case traffic was intercepted.

Frequently asked questions

Is WPA2 still safe?

WPA2 with a long passphrase is still reasonable for most homes. WPA3 is better, so use it or WPA3 transition mode if your router and devices support it.

How often should I check my router?

Turn on automatic updates if you can, and log in every three months to confirm the firmware is current, remote management is off and no unknown devices are connected.

Should I turn my router off when I go away?

The ACSC suggests it as a precaution when nobody is home. Check first that nothing relies on it, such as security cameras or an alarm.

Does a VPN secure my home network?

No. A VPN encrypts traffic leaving one device. It does not change your router's passwords, firmware or settings, which are what attackers target.

My internet provider supplied the router. Who updates it?

Many providers push firmware updates to their own routers automatically, but not all do, and older models stop getting them. Log in or open the provider's app to check the firmware date, and ask the provider for a replacement if it is no longer supported.

Tools that help

Related guides

Sources