Default router passwords and open admin panels are how most home networks in Dhaka get taken over. These are the settings worth changing today.
Almost every home network compromise we are asked to help with comes down to one of five things. None of them need technical skill to fix.
1. Change the router admin password
The WiFi password and the router login password are different. The second one is very often still admin/admin. Anyone already on your WiFi can open the admin panel and change your DNS to point at a phishing server. Change it first.
2. Use WPA2 or WPA3, never WEP or open
If your router still offers WEP, treat it as no security at all. WPA3 if the router supports it, WPA2-AES otherwise.
3. Turn off WPS
WPS push-button pairing has a known flaw that lets an attacker recover your WiFi password by brute-forcing an eight digit PIN. There is no good reason to leave it on.
4. Disable remote administration
Unless you specifically need to log into your router from outside your home, remote admin should be off. This is the single most common way DVRs and routers with real IPs get hijacked.
5. Update the firmware, then check again in a year
Router vendors do patch serious flaws, but no router installs updates on its own. Check the admin panel once, apply what is there, and put a reminder in your calendar.
If you are our customer and any of this feels unfamiliar, call support and we will go through it with you on the phone. It takes about five minutes.