What to do if…
your router settings show remote administration was turned on and you did not enable it
Short answer
Keep the router powered if you need local access, but disconnect its internet access for now. Then turn remote administration off, change the router admin password, and update or reset the router if you cannot trust the settings.
Do not do these things
- Don’t leave the router connected to the internet just to see what happens.
- Don’t reuse a password from any other account for the router admin login.
- Don’t assume changing the Wi-Fi password fixes router admin access.
- Don’t install firmware from pop-ups, emails, forums, or random download links.
- Don’t let anyone claiming to be your ISP remote-control your device unless you contacted the ISP through a verified route.
- Don’t make lots of unrelated changes without noting what you changed.
What to do now
-
Get the router to a safer pause.
Unplug the WAN or internet cable, or switch off the separate modem if you have one. Keep the router powered if you need to log in to its local admin page. -
Record the suspicious settings before changing them.
Take photos or screenshots of the remote administration setting, admin users, DNS settings, port forwarding rules, firewall rules, device list, logs or system events, and firmware version. -
Log in locally, not from outside your network.
Use Ethernet if you can. If you must use Wi-Fi, connect only to your own network and type the router address directly into the browser. -
Turn off remote administration.
Disable settings with names such as remote management, remote admin, web access from WAN, admin from internet, or remote access. If a cloud or app-based remote access setting appears to be managed by your ISP, leave the router offline and check with your ISP through its official website, app, or phone number. -
Change the router admin login.
Set a strong, unique admin password. Change the admin username if the router allows it, enable 2-step verification if the router offers it, and use any option that logs out other admin sessions. -
Check the settings most often abused after router access.
Set DNS back to automatic, or to a trusted DNS provider you chose. Remove port forwarding or firewall rules you did not create. Turn off WPS. Turn off UPnP if you do not specifically need it, and note the change so you can reverse it if a device stops working. -
Update the router using only a trusted route.
Use the router’s built-in update page, your ISP’s official app, or the manufacturer’s official support page. Reboot after the update and check again that remote administration is off. -
Reset the router if you cannot regain control.
Do a factory reset if settings keep returning, unknown admin users remain, the admin password cannot be changed, or the router is no longer supported. Rebuild the settings from scratch and do not import an old saved configuration unless you fully trust it. -
Change Wi-Fi details after the router admin side is secured.
Set a new Wi-Fi password using WPA2 or WPA3 if available. Consider changing the Wi-Fi network name, then reconnect devices one at a time. -
Secure key accounts if you notice signs beyond the router.
If you see unknown logins, password manager alerts, banking alerts, or email changes, secure your email first, change affected passwords, turn on 2-step verification, and sign out other sessions where the service allows it. -
Report it only if you think a crime or fraud happened.
In England, Wales or Northern Ireland, Report Fraud is the main reporting route for cyber crime and fraud. In Scotland, use Police Scotland on 101 for non-emergencies. If there is immediate danger or a crime is in progress, call 999.
What can wait
- You do not need to decide who changed the setting right now.
- You do not need to replace every device before securing the router.
- You do not need to rebuild the whole home network today unless you cannot regain control.
- You do not need to contact everyone in the household until you have stabilised access and set new Wi-Fi details.
Important reassurance
An unexpected remote administration setting is worth taking seriously, but it does not prove everything on your network is compromised. Taking the router offline, turning remote access off, and changing the admin login are useful first steps even if the cause turns out to be a mis-click, an update, or an ISP-managed change.
Scope note
These are first steps to stabilise the situation and reduce further access. Later decisions, such as replacing the router, investigating logs, or dealing with fraud, may need help from your ISP, the router manufacturer, police reporting routes, or a reputable security professional.
Important note
This is general information, not professional security, legal, financial, or technical advice. Router menus and ISP equipment vary; if you are unsure about a setting, keep the router offline from the internet and use verified support through your ISP or the manufacturer.
Additional Resources
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.