How to Secure an Old Wi-Fi Router From DNS Hijacking

To secure an old Wi-Fi router from DNS hijacking, update its firmware, replace both the administrator and Wi-Fi passwords, disable internet-facing remote management, verify its DNS settings, and retire it if the manufacturer no longer provides security updates. If you already see unfamiliar DNS addresses, changed settings, or certificate warnings, disconnect the router from the internet and perform a clean factory reset before reconnecting it.
This is not a theoretical concern. In 2026, the FBI and NSA warned that Russian military intelligence had exploited vulnerable home and small-office routers, altered their DNS settings, and used fraudulent responses to intercept selected traffic. The practical defenses are straightforward, but the order matters—especially if your internet provider requires connection credentials that a reset would erase.
What DNS hijacking does to a router
DNS is the system that translates a name such as example.com into the IP address used to reach the site. Most phones and computers receive DNS and network settings automatically from the router through DHCP.
If an attacker changes the router's DNS resolver, every connected device may inherit the malicious setting. The compromised resolver can monitor domain lookups or return a false address for a selected service. A user may then be sent to an imitation login page even though the domain name appears familiar.
The FBI's April 7, 2026 public service announcement described attackers modifying DHCP and DNS settings on compromised routers. The alert emphasized that bypassing a browser or email certificate warning could expose traffic and allow passwords, authentication tokens, and other sensitive information to be stolen.
Before changing anything: identify the exact router
Find the manufacturer, model number, and hardware revision on the label underneath or behind the router. Hardware revision matters because two devices with the same marketing name may use different firmware.
Then check the manufacturer's official support page for three things:
- The newest firmware version and its release date
- Whether the model is still supported
- Whether any published security notices apply to the model or hardware revision
If your internet provider supplied the router, ask whether firmware is installed automatically and whether a supported replacement is available. Do not download firmware from a forum, file-sharing site, or an unofficial “driver update” page.
Save the connection details before a factory reset
A reset can erase the settings required to connect to your internet provider. Before resetting, record the connection type and any ISP-supplied username, VLAN ID, telephone configuration, or other required values. If the router includes a modem or handles fiber authentication, contact the provider when you are unsure.
Take screenshots of important settings, but do not rely on restoring an old configuration backup if compromise is suspected. A backup may reintroduce the malicious DNS address or insecure option you are trying to remove.
How to secure an old Wi-Fi router step by step
1. Open the router settings locally
Connect by Ethernet when possible. Otherwise, join the router's Wi-Fi while at home. Open its local management address—commonly shown on the router label or in the network details on your device.
Avoid administering the router from public Wi-Fi or through an internet-facing management page. If the browser warns that the local page uses a self-signed certificate, compare the address with the manufacturer's instructions. A certificate warning on an ordinary public website or email login is different: do not continue past it.
2. Install the latest official firmware
Use the router's built-in update function or follow the manufacturer's exact manual-update process. Keep the router plugged in and do not interrupt power during installation. Confirm that the firmware is for the correct model and hardware revision.
The NSA's April 2026 router warning specifically recommends installing current firmware and upgrading devices that have reached end of support.
3. Factory-reset the router if compromise is possible
If DNS values changed unexpectedly, unknown administrator accounts appear, remote management turned itself on, or a relevant vulnerability was exploited before you patched it, a clean reset is safer than simply correcting one setting.
- Disconnect the internet/WAN cable or fiber terminal connection.
- Hold the physical reset button for the time specified by the manufacturer.
- Reconnect locally and install current firmware if needed.
- Configure the router manually rather than restoring the old backup.
- Reconnect the WAN only after the administrator password and essential security settings are complete.
4. Change both router passwords
Your router normally has two different credentials:
- Administrator password: controls the router's settings.
- Wi-Fi password: lets devices join the wireless network.
Replace default or reused values with separate, unique passwords. Store them in a password manager. If the interface permits changing the administrator username, replace predictable values such as admin as an additional measure—but a strong password remains essential.
5. Use WPA3 or WPA2-AES
Select WPA3-Personal when all important devices support it. WPA2-Personal with AES is an acceptable compatibility option for many older devices. Do not use WEP, WPA, or WPA2 with TKIP.
The FTC's home Wi-Fi guidance recommends WPA3 or WPA2 and advises replacing a router if updated software still cannot provide those choices.
6. Disable remote management from the internet
Look for settings named Remote Administration, Web Access from WAN, Internet Administration, or Remote GUI. Turn them off unless you have a specific, secured business requirement.
Local management from a device already connected to your network should continue to work. This single change prevents the administration page from being exposed directly to internet scans and password attacks.
7. Turn off WPS and review UPnP
Disable Wi-Fi Protected Setup, especially PIN-based WPS. Review Universal Plug and Play as well. UPnP can make gaming and smart-device setup easier, but it also lets local apps create router port mappings automatically. If you do not need it, turn it off.
After disabling UPnP, verify that games, video calls, or devices you rely on still function. If something requires an inbound port, create only the specific rule you need and document it.
8. Verify DHCP and DNS settings
Open the internet/WAN and LAN/DHCP sections. Check the primary and secondary DNS server addresses. They may be:
- Assigned automatically by your ISP
- Set to a resolver you deliberately chose
- Set to the router's own local address, with the router forwarding queries upstream
An unfamiliar address is not proof of compromise, but it deserves investigation. Compare it with your ISP's documentation or the official documentation of your chosen DNS provider. If you use an encrypted resolver, our guide to encrypted DNS alternatives explains the differences among several established services.
9. Remove unknown rules and accounts
Review administrator users, port forwarding, dynamic DNS, VPN server, static routes, and firewall exceptions. Remove entries you did not create. Confirm that the router firewall is enabled.
Do not delete an ISP management account or telephone setting without checking with the provider. ISP-supplied hardware may contain legitimate entries that are not present on retail routers.
10. Separate guests and smart devices
Create a guest or IoT network with client isolation if the router supports it. Put visitors, smart plugs, cameras, and other less-trusted devices there instead of on the same network as computers and storage devices.
A guest network is not a substitute for updates, but it can reduce how easily a compromised device reaches more sensitive equipment.
How to tell whether the router may be compromised
One sign alone rarely proves an intrusion. Treat several of these together as a reason to reset the router and change important account passwords:
- DNS addresses or DHCP settings changed without your approval
- New administrator accounts or an administrator password that no longer works
- Remote management, port forwarding, or dynamic DNS enabled unexpectedly
- Frequent redirects to unfamiliar login pages
- Certificate warnings on well-known websites or email services
- Devices repeatedly using a search engine or homepage you did not select
- A security notice confirms that your exact firmware version is vulnerable
Slow Wi-Fi by itself is not reliable evidence; interference, congestion, and ISP problems are much more common causes.
Never ignore a certificate warning after a redirect
A malicious DNS server can point a familiar domain toward the attacker's server, but it normally cannot present a valid TLS certificate for that domain. The browser warning is therefore an important barrier.
Do not click “continue,” install a certificate, or enter credentials. Close the page, disconnect from the network, and test through a trusted mobile connection. If you entered a password after bypassing a warning, change it from a known-clean device, revoke active sessions, and replace any exposed authentication tokens or app passwords.
Passkeys offer strong phishing resistance, but recovery still needs planning. See what happens to your credentials in our guide to recovering passkeys after losing a phone.
When an old router must be replaced
Replace the device when any of the following is true:
- The manufacturer says it is end-of-life or end-of-support
- No security firmware has been released despite known applicable vulnerabilities
- WEP or original WPA are the strongest wireless security options
- Remote administration cannot be disabled
- The device repeatedly changes settings after a clean reset and verified update
Installing the latest available firmware does not make an unsupported router safe forever. “Latest” may simply mean the final old release. CISA's 2026 guidance on end-of-support edge devices emphasizes replacing equipment that can no longer receive security fixes.
What to do after securing or replacing it
- Reconnect devices and make sure they receive the expected DNS settings.
- Check that the public DNS resolver and IP address match your intended setup.
- Confirm that remote management is not reachable from mobile data.
- Remove the old Wi-Fi network from devices if you changed its name.
- Update connected computers, phones, cameras, and smart devices.
- Change sensitive passwords if you suspect interception, starting with email and password-manager accounts.
A VPN can protect traffic after it leaves your device, but it does not repair a compromised router or make certificate warnings safe to bypass. Our explanation of VPN tracking and traffic analysis covers what a VPN does and does not hide.
Frequently asked questions
Will changing the Wi-Fi password remove malware from a router?
No. It removes unauthorized wireless clients, but it does not repair altered firmware or administrator settings. Update the firmware and perform a clean factory reset when compromise is suspected.
Should I use automatic DNS or set my own?
Either can be safe when intentional and documented. Automatic DNS relies on the ISP; a manually chosen resolver shifts trust to that provider. The key is verifying that the displayed addresses are the ones you selected.
Does rebooting fix DNS hijacking?
Usually not. A reboot preserves saved settings. A factory reset erases them, but you must also update the firmware and secure the administrator account to reduce the chance of reinfection.
Can antivirus detect a hacked router?
Endpoint security may warn about redirects or suspicious certificates, but it cannot reliably prove that the router itself is clean. Inspect the router configuration, firmware status, and vendor advisories.
Is an ISP router safer than buying my own?
It depends on update support and configuration. ISP equipment may receive automatic updates and replacement support; retail equipment may offer more control. In either case, verify the support lifecycle and disable unnecessary internet-facing administration.
The bottom line
The most important router-security decision is supportability. A router that still receives patches can usually be hardened with updated firmware, unique credentials, WPA3 or WPA2-AES, disabled remote management, and verified DNS settings. A router that no longer receives security fixes should be replaced, even if it still delivers acceptable Wi-Fi speed.
If you suspect DNS hijacking, do not merely change one resolver address. Preserve required ISP details, disconnect the WAN, reset and update the router, configure it manually, then change sensitive credentials from a clean connection.
Sources
- FBI/IC3: Russian GRU Exploiting Vulnerable Routers to Steal Sensitive Information, April 7, 2026
- NSA: Defensive recommendations for vulnerable home and small-office routers
- CISA: Improve Router Hygiene to Protect Against Russian State-Sponsored Targets, July 13, 2026
- FTC: How to secure a home Wi-Fi network


