Menu

We independently review everything we recommend. When you buy through our links, we may earn a commission. As an Amazon Associate we earn from qualifying purchases.

How To

How to Disable WPS and UPnP to Harden Your Router

Owen Bradley Owen Bradley Aug 8, 2026 10 min read 14 views
Try Amazon Prime free for 30 days Fast delivery, Prime Video and Prime Music Start free trial

Two features on almost every home router exist purely for convenience, and both undermine the security everything else is trying to provide. WPS lets a guest join wifi by pressing a button or typing an eight-digit code, and that code has a well-documented weakness that lets an attacker in range recover your wifi password. UPnP lets any application on your network ask the router to open a port to the internet, with no confirmation and no record you would notice. Disabling WPS and UPnP takes about five minutes and closes two of the easiest routes into a home network. This guide covers how to turn both off, what stops working afterwards, and the safer alternatives for the consoles and apps that genuinely relied on them.

Home wifi router rear panel with WPS button used for network setup

Why WPS Is a Problem

Wi-Fi Protected Setup was designed so people could connect a printer or a laptop without typing a long passphrase. It offers two methods. The push-button method requires physical access to the router and is comparatively safe, though it does leave a short window during which any nearby device can join. The PIN method is the dangerous one.

The eight-digit PIN is validated in two halves, and the router reveals whether each half is correct. That design reduces the number of guesses required from tens of millions to a few thousand, which an automated tool in radio range can work through in hours. Once the PIN is recovered, so is your wifi password, and changing that password does not help because the PIN still works. Worse, many routers keep the PIN method enabled even when the push-button feature appears switched off, and the PIN is often printed on the label where any visitor can read it.

Why UPnP Is a Problem

Universal Plug and Play solves a real annoyance: games, media servers and video-call apps need inbound ports, and configuring them manually is tedious. UPnP lets software request those ports automatically. The flaw is that the router grants requests without authenticating who asked. Any program on your network, including malware, a compromised smart device or a browser page exploiting a vulnerable implementation, can open a path from the internet to itself.

The result is a firewall whose rules any local program can rewrite. Devices you never think about, such as cameras and media boxes, routinely open ports and leave them open long after the app has closed. Some older implementations even accepted requests arriving from the internet itself, exposing the network directly.

Before You Start

  • Your router admin address and password. Usually 192.168.1.1 or 192.168.0.1, printed on the device label.
  • Your actual wifi password. If you have always joined devices with the WPS button, find or reset the passphrase first, or you will not be able to add anything afterwards.
  • A configuration backup. Export current settings so you can restore quickly if something unexpected breaks.
  • A list of devices that use port forwarding. Consoles, security recorders and self-hosted servers may need manual rules once UPnP is gone.
  • Current firmware. Update first, since older builds sometimes re-enable these features or ignore the toggle entirely.

Step-by-Step: Disabling WPS

  1. Open the admin interface. Type the router address into a browser and sign in. If you have never changed the default admin password, do that now, because it matters more than either feature you are about to disable.
  2. Find the wireless settings. Look under Wireless, Wi-Fi, WLAN or Advanced. WPS may sit on its own page or be buried under a security or setup sub-tab.
  3. Disable the PIN method explicitly. Look for entries labelled Router PIN, WPS PIN, Device PIN or Client PIN and switch them off. This is the critical step, and on many models it is a separate control from the main WPS toggle.
  4. Disable WPS entirely. Turn off the main WPS or Wi-Fi Protected Setup switch. If your router runs separate 2.4GHz and 5GHz configurations, check both bands, and check any guest network too.
  5. Save and reboot. Apply the change, then restart the router so nothing lingers in memory.
  6. Verify it stayed off. Log back in and confirm the setting reads disabled. Press the physical WPS button and check that no pairing window opens. Some routers silently re-enable WPS after a firmware update, so recheck after each one.

Laptop showing router admin settings while disabling WPS and UPnP features

Step-by-Step: Disabling UPnP

  1. Review what UPnP has already opened. Before switching it off, find the UPnP page and look for a port map or forwarded ports table. Write down every entry, including the internal device and port numbers, since this is your record of what actually depended on the feature.
  2. Locate the UPnP setting. It usually lives under Advanced, NAT Forwarding, WAN, or a page named UPnP. Some interfaces call it NAT-PMP or list both, and NAT-PMP should be disabled alongside UPnP because it does the same job.
  3. Turn it off and save. Uncheck the enable box and apply. Existing mappings may persist until reboot.
  4. Reboot the router. This clears any mappings still held in memory.
  5. Confirm the table is empty. Return to the port map page and check that no dynamic mappings remain. Also review the manual port forwarding page and delete any entry you no longer recognise or use.
  6. Test your network normally. Browse, stream, take a video call and run any smart home routines. Most activity is unaffected because it uses outbound connections that never needed UPnP.
  7. Add manual rules only where needed. If a specific application genuinely fails, look up the exact ports it requires and create a single forward to that device’s reserved address rather than re-enabling UPnP wholesale.

What Actually Breaks Afterwards

Far less than most people expect. Web browsing, streaming, email, cloud backups and virtually all smart home devices use outbound connections and are unaffected. Video calls on the major platforms work fine because they relay through the provider’s servers when direct connections are unavailable.

The genuine casualties are narrower. Game consoles may report a stricter NAT type, which can slow matchmaking or block voice chat in some titles. Peer-to-peer clients lose incoming connections and run slower. Self-hosted services, such as a media server you reach from outside the house or a security recorder with remote viewing, stop being accessible remotely until you forward their ports by hand.

Safer Alternatives for Consoles and Remote Access

For a console, reserve a fixed IP address for it in the DHCP settings, then create manual forwards for the ports the platform publishes. That achieves the same open NAT with a rule you wrote deliberately, aimed at one device, instead of a blanket permission any program can use. Routers with a clear rule table make this quick, and the best routers for port forwarding generally let you reserve an address and add the forward from the same page.

For remote access to a home server or camera, a VPN back into your network is the stronger option. Many modern routers include a built-in VPN server, so you connect to the router from outside and reach everything internally without exposing a single service to the internet. If yours lacks that, it is a strong reason to look at the best firewall routers, which usually bundle a VPN server alongside proper rule control.

Common Mistakes to Avoid

The most frequent error is disabling the WPS button while leaving the PIN active. The PIN is the vulnerable half, so if you only see one toggle, dig through the advanced wireless pages until you find the PIN control specifically. On a few models the PIN cannot be disabled at all, which is a genuine reason to replace the hardware.

Another is turning off UPnP without first recording the existing port mappings. When something stops working a week later, that list is the only clue to what it needed. Equally common is re-enabling UPnP at the first sign of trouble instead of adding one targeted forward, which undoes the whole exercise.

Finally, do not treat these two changes as the finish line. An easily guessed admin password, outdated firmware or weak wireless encryption leaves the network exposed regardless. Modern encryption is the other half of the job, and the best WPA3 routers address it directly, while a broader review of how to secure your home network from hackers covers the remaining steps.

Network equipment and cabling in a secured home network setup

What to Do If the Settings Are Missing

Some budget and provider-supplied routers hide these controls or omit them entirely. If your interface has no WPS or UPnP option, check whether the provider offers a separate management app, since features are sometimes exposed there instead. Ask support to disable them remotely if the admin interface is locked down.

Where neither is possible, you have three practical options. Put the provider unit into bridge or modem-only mode and run your own router behind it, which gives you full control of every setting. Replace the unit outright with retail hardware, which is often cheaper over a few years than renting. Or, at minimum, place untrusted devices on an isolated guest network to limit what an exploited feature could reach. Hardware chosen for security rather than price, such as the best secure wifi routers, exposes these toggles plainly instead of hiding them.

Frequently Asked Questions

Is the WPS push button safe if I disable only the PIN?

The button method is considerably safer because it requires physical access and works for a short window. Disabling the PIN removes the serious vulnerability. Turning both off is still preferable, since the button can be pressed by anyone who reaches the router.

Will my wifi devices disconnect when I disable WPS?

No. Devices already connected keep their stored password and stay online. WPS only affects the process of joining a new device, which you will do by entering the passphrase instead.

Do I need UPnP for online gaming?

Not necessarily. Many games work fine without it, though some report a stricter NAT type. Manual port forwarding to a console with a reserved IP address delivers the same result with far less exposure.

Does disabling UPnP slow my internet down?

No. Normal browsing and streaming use outbound connections that never involved UPnP. Only peer-to-peer transfers that depend on inbound connections are affected.

How often should I check these settings?

After every firmware update and after any factory reset, since both can restore defaults. A quick check twice a year is a sensible habit, and it takes under a minute once you know where the pages are.

Final Thoughts

WPS and UPnP trade a small amount of convenience for a disproportionate amount of risk, and switching both off is one of the highest-value changes you can make to a home network. Find your wifi passphrase first, record any port mappings UPnP created, disable the WPS PIN explicitly rather than trusting a single toggle, then reboot and verify the settings held. Replace what you lose with deliberate rules: a reserved address and a manual forward for the console, a VPN for remote access. Do that once, recheck it after firmware updates, and your router in 2026 will be meaningfully harder to reach than the default it shipped with.

Try Amazon Prime free for 30 days Fast delivery, Prime Video and Prime Music Start free trial

More reviews across the web

10