The fastest security upgrade we ever made to our home network cost nothing and took eleven minutes: we logged into the router and turned five things off. No new hardware, no subscription — just closing doors the router had been holding open out of politeness.
Router makers ship these features enabled because they reduce support calls, not because your home needs them. Here’s what each one actually is, why it’s risky, how to switch it off, and — because nothing is free — what genuinely breaks and how to cope. That last part matters: advice that pretends there are no trade-offs is how settings get quietly turned back on a week later.
The five, at a glance
| Setting | What it does | Risk | Verdict |
|---|---|---|---|
| UPnP | Lets devices open firewall holes automatically | High | Off for almost everyone |
| WPS | Push-button / PIN WiFi joining | High | Off, period |
| Remote management (WAN admin) | Exposes admin panel to the internet | High | Off; use the vendor app instead |
| WEP/WPA legacy modes | Ancient WiFi encryption | High if in use | Move to WPA2/WPA3 |
| Router-side WiFi analytics/telemetry | Shares usage data with vendor/partners | Privacy | Off; costs nothing |
1. UPnP — the automatic door-opener
What it is. Universal Plug and Play lets devices on your network tell the router, “open a path from the internet to me,” and the router complies. Automatically. Without asking you, without a password, without a log entry you’ll ever read. It exists so game consoles and apps could work without anyone learning what port forwarding is.
Why it’s risky. Your firewall’s whole job is blocking unsolicited inbound traffic — we covered what it does and doesn’t catch here. UPnP hands every device in the house a master key to that firewall. The threat isn’t your Xbox; it’s the weakest device you own. One compromised smart plug or malware-infected laptop can use UPnP to punch a hole exposing whatever it likes — and malware has been abusing exactly this for years. Worse, some router implementations have historically answered UPnP requests from the internet side, turning the automatic door-opener into a public one. It’s part of why the NSA’s home network security best practices recommend disabling UPnP on home routers.
How to turn it off.
- eero: app → Settings → Network Settings → UPnP → off.
- TP-Link Deco: app → More → Advanced → UPnP → off.
- Netgear:
routerlogin.net→ Advanced → Advanced Setup → UPnP → untick “Turn UPnP On.” - Asus:
router.asus.com→ WAN → toggle “Enable UPnP” to No.
What breaks, honestly. This is the one with real trade-offs. Game consoles may report “strict NAT” and struggle to host multiplayer lobbies or voice chat. Some IP cameras’ remote viewing and some torrent/self-hosting setups lose inbound connectivity. The fix is a manual port forward for each specific device and port — five minutes per rule, in the same admin section. That’s not busywork; it converts “anything can open anything” into “these two doors, which I chose, to these two devices.” In our house, exactly one rule was needed after shutting UPnP off, for one console, and evening Rocket League continued without complaint.
2. WPS — the button that trusts everyone
What it is. WiFi Protected Setup: press the button (or enter an 8-digit PIN) and a device joins the network without the password.
Why it’s risky. The PIN mode has a design flaw known for well over a decade: the router confirms the PIN in two halves, collapsing the guessing work from millions of combinations to a few thousand — automatable from the parking lot on many older routers. And button mode means anyone with thirty seconds of physical access (the cable guy, a party guest, a curious teenager’s friend) joins your network invisibly and permanently.
How to turn it off. Netgear: Advanced → Wireless Settings → disable the WPS options. Asus: Wireless → WPS tab → off. Mesh systems like eero and Deco largely dropped WPS — one of several reasons we like them for families; see our router reviews.
What breaks. Nearly nothing. You’ll type the WiFi password once per new device — or share a QR code, which is both easier and safer. A handful of old WiFi printers used WPS for setup; all of them also support ordinary password entry, just more grumpily.
3. Remote management — your admin panel, on the public internet
What it is. A setting (also “Remote Access,” “Web Access from WAN”) that makes your router’s admin page reachable from anywhere on the internet — you, on vacation, tweaking your DNS. Also: everyone else on earth, trying passwords against it.
Why it’s risky. Internet-exposed router admin panels are one of the most systematically scanned-for targets that exist. Automated tools sweep the whole address space for them around the clock, then try default and leaked passwords plus known firmware exploits. Exposed management is a leading way home routers end up in botnets — and if you’ve ever wondered whether your router’s been hacked, this setting is suspect number one.
How to turn it off. Netgear: Advanced → Remote Management → disable. Asus: Administration → System → “Enable Web Access from WAN” → No. Deco (web panel): Advanced → Remote Management → off.
What breaks — and the honest nuance. Old-style WAN web access: turn it off; you lose tweaking-DNS-from-a-beach, which you weren’t doing. But note the distinction: modern app-based cloud management (eero, Deco, Asus Router app) is a different mechanism — the router connects out to the vendor’s service; nothing listens on your public address. Don’t disable that; instead, protect the vendor account with a strong unique password and two-factor authentication. A password manager makes both painless, and a hardware key like the YubiKey 5C NFC locks the account that controls your entire network.
4. Legacy encryption — WEP and WPA1
What it is. Old WiFi encryption modes kept around for compatibility. WEP can be cracked in minutes with free tools; original WPA isn’t much better.
How to fix it. In your wireless settings, set security to WPA2-Personal or WPA2/WPA3 (pure WPA3 if every device supports it; mixed mode if not). Avoid “WPA/WPA2 mixed,” which lets devices negotiate down to the broken protocol.
What breaks. Only genuinely ancient hardware — think a 2008 handheld game or a first-generation smart gadget. If one device is forcing your whole network onto broken encryption, the device should go, not the encryption. (A guest network can be a hospice for such stragglers — setup guide here — though retirement is still the right call.)
5. Vendor telemetry and “WiFi analytics”
What it is. Many routers ship with usage analytics, “network diagnostics,” or partner data-sharing enabled — details of your traffic patterns flowing to the manufacturer.
Why we turn it off. It’s a privacy cost with zero benefit to you, and every data pipeline out of your home is one more thing that can leak. Look under Administration, Privacy, or the app’s account settings for analytics/telemetry toggles. Nothing breaks. Nothing. This is the freest win on the list. (For traffic that leaves your house anyway, on networks you don’t control, that’s what a VPN like Proton VPN is for.)
The eleven-minute checklist
- Log into your router (sticker on the bottom has the address).
- UPnP off. Note anything that complains over the next week; add one manual port forward per genuine complaint.
- WPS off. No exceptions.
- WAN remote management off; add 2FA to the router vendor’s app account instead.
- Encryption to WPA2/WPA3.
- Telemetry toggles off.
- While you’re in there: confirm the admin password isn’t the default, and check for a firmware update.
The bottom line
Every one of these five settings trades a sliver of convenience for a real reduction in how attackable your home is — and the total convenience cost, in our actual house, was one manual port-forwarding rule and typing a WiFi password slightly more often. If working through your router’s admin maze left you wanting settings that are designed to be understood — with per-device visibility and sane defaults out of the box — that’s the argument for upgrading the gateway itself: the GL.iNet Flint 2 gives tinkerers full control at a modest price, and our firewalls guide covers the set-and-forget options for everyone else.
