Yahoo
Skip to main content
Advertisement
Advertisement
Advertisement
Advertisement

Your router has 6 security holes you probably don't know about

The back Ethernet and SFP+ ports of the Unifi Dream Router 7.
Patrick Campanale / How-To Geek

Routers, while important, are not the most interesting bit of tech, and most people aren't interested in learning what all those toggles in the settings actually do.

There's mostly no problem with this, but the thing is, you can't trust the default settings to actually be the best match for your setup. There will nearly always be a few things toggled on by default that would serve you better switched off. Here are the six I'd tell you to cut unless you can explain, out loud, exactly why you need them.

UPnP (Universal Plug and Play)

The setting that lets any gadget punch a hole in your firewall

ASUS ROG Xbox Ally X lying on a floor.

UPnP is the reason your Xbox or smart TV can just "work" online without you ever touching a settings page. It lets devices on your network ask the router to open ports for them automatically.

Advertisement
Advertisement

Super convenient, right? The catch is that UPnP has no authentication whatsoever.

Your router trusts any device that asks, and that's fine when it's your console, but if a single sketchy device or a bit of malware sneaks onto your network, it can effortlessly open doors straight to the internet. It's the kind of hole that got roughly 100,000 home routers hijacked into a spam-spewing botnet , purely because they had UPnP sitting exposed.

The good news is that everyday stuff (browsing, streaming, video calls) doesn't need it at all, so I keep it off. If one specific game or console genuinely needs a port, forward that one port manually instead .

WPS (Wi-Fi Protected Setup)

That "convenient" button is handing out your Wi-Fi

A basic ISP-issued router.

Monica J. White / How-To Geek

WPS was invented so you could connect a device without typing your password, either by pressing a button on the router or punching in an eight-digit PIN. Sounds harmless, but it kind of isn't. That PIN gets checked in two separate halves, which means an attacker isn't cracking one eight-digit code, they're cracking a four-digit code followed by a three-digit code (the final digit is just a checksum).

Advertisement
Advertisement

Cheap tools can brute-force that in hours, sometimes minutes, which makes your lovely strong Wi-Fi password basically pointless. The button method isn't much better, since it opens a two-minute window where anyone within range can hop on. Modern phones dropped WPS years ago in favor of QR codes and newer standards, anyway. There's no real downside to switching it off, so switch it off.

Remote management

Your router's control panel should not be reachable unless you desperately need it

A Chromebook running btop with a router, Raspbery Pi, and NAS in the background.

Jordan Gloor / How-To Geek

Your admin page (the one at 192.168.1.1 or similar) should only be reachable when you're actually home, on your own Wi-Fi or Ethernet. Remote management, sometimes labeled remote administration or web access from WAN, throws that page open to the wider internet so you can log in from anywhere.

The problem is that "anywhere" includes every bot on the planet that knows your public IP and wants to brute-force its way in. From there, someone can hijack your DNS, reroute your traffic, and lock you out of your own router. Unless you do IT for a living, you will basically never need this, and it's a wide-open front door most people don't even know exists. Turn it off!

DMZ host

This one rips the armor off a device completely

A Pixel 10 Pro phone plugged into a router via USB.

Goran Damnjanovic / How-To Geek

DMZ host is the nuclear option people reach for when port forwarding feels like too much work. Flip it on, point it at a device, and your router forwards all incoming traffic to that device while stripping away its firewall protection entirely. It's like taking one computer in your house and setting it directly on the open internet with nothing in front of it.

Advertisement
Advertisement

Folks usually enable it to fix a stubborn gaming or connection issue, but it's a terrible trade. If that exposed device ever gets compromised, the attacker has a comfy launchpad to poke at everything else on your network. In almost every case, a couple of targeted port forwarding rules do the same job without taking the DMZ host risk. Also, you can tell how extreme it is just by the name: "De-Militarized Zone!"

Port forwarding rules you didn't set up yourself

Old open doors you forgot were even there

Ethernet cables plugged into a Ubiquiti Flex Mini managed network switch.

Jordan Gloor / How-To Geek

Port forwarding itself is fine and plenty useful when you mean to do it, like exposing a NAS or a game server. The danger is the leftover stuff. Maybe a game from three years ago had you open a range of ports, or your ISP's tech added a rule during setup, or you experimented once and forgot.

Every one of those rules is a direct path from the internet to a device inside your home, and if that device has an unpatched flaw, that's your whole network at risk. So pop into the port forwarding section and actually read the list. Anything you don't recognize or no longer use, delete it.

USB file sharing, media servers, and cloud access

The bonus features that tax your little router

Two USB flash drives plugged into a computer.

Ismar Hrnjicevic / How-To Geek

A lot of routers come loaded with extras: USB file sharing over SMB or FTP, a built-in DLNA media server, personal cloud storage, remote file access, the works.

Advertisement
Advertisement

If you're using them on purpose, great. If you're not, they're doing two annoying things: first, each one is another service listening for connections, which is more surface area for an attacker.

Second, router CPUs are weaklings, and running these background services can drag down your actual internet speed for no reason. My rule is simple: if you're not actively using a feature, turn it off.

And while you're in there, stick your random smart gadgets on a properly isolated guest network so they can't wander into your main one.


The rule of thumb I give everyone

If you can't explain why a setting is on, turn it off. That single habit covers you better than any single toggle, and it pairs nicely with the boring basics that do the real protecting , like a strong admin password and up-to-date firmware. Leave the fancy stuff off, flip it on only when you've got a reason, and your network will be quieter, faster, and a whole lot harder to mess with.

Advertisement
Advertisement
Mobilize your Website
View Site in Mobile | Classic
Share by: