How to Disable WPS on Your Router and Why You Should (2026) Expert Guide

To disable WPS on your router, log in to your router’s admin panel at 192.168.1.1 or 192.168.0.1, navigate to the Wireless or WPS settings, and toggle WPS off. I disable WPS on every router I set up because the feature introduces a serious brute-force vulnerability that puts your entire wireless network at risk, even when you use a strong Wi-Fi password.

WPS exists on most routers shipped in the last 15 years, and the majority of home users never touch the setting. According to community research and security advisories, the PIN method can be cracked in a matter of hours with off-the-shelf tools. In this guide, I’ll walk you through what WPS is, why disabling it matters, and exactly how to disable WPS on your router regardless of brand.

Table of Contents

What Is WPS (Wi-Fi Protected Setup) and Why Does It Exist?

WPS stands for Wi-Fi Protected Setup, and it is a networking standard created in 2006 to make connecting devices to a wireless network easier. Instead of typing a long WPA2 password, you could press a button or enter a short PIN, and the device would join the network automatically.

The feature was designed for the average home user who found WPA2 passwords too complicated. Adding a new printer, smart TV, or game console often meant reading off a 16-character password across the room. WPS removed that friction for a few seconds of setup time.

WPS is enabled by default on most routers manufactured between 2007 and 2018. The Wi-Fi Alliance built the standard into the vast majority of consumer routers, access points, and range extenders. If you have not touched your router settings in years, chances are WPS is still on right now.

Common use cases included wireless printers that had no display for typing passwords, older smart TVs that lacked on-screen keyboards, and IoT devices where entering a long password was impractical. These were real pain points, and WPS solved them in 2006. The technology has not aged well, especially when you look at the security implications.

Key Takeaway: WPS (Wi-Fi Protected Setup) is a router feature that lets devices join your Wi-Fi network without typing a password, using either a button press or an 8-digit PIN. It was designed for convenience but is now considered a security liability.

How WPS Works: Push-Button vs PIN Method

WPS supports two main connection methods, and they have very different security profiles. Understanding both is essential before you decide whether to disable WPS on your router.

The Push-Button Method

When you press the WPS button on your router, the device enters pairing mode for about 1 to 2 minutes. During this pairing window, any WPS-compatible device within range can join your network without a password. The connection completes automatically, and the router closes the pairing window when the timer expires or when a device connects.

The push-button method is comparatively safe because an attacker would need physical access to press the button at the same time as your device. There is no way to trigger pairing mode remotely. The biggest risk is accidental press, like when you are cleaning or moving the router.

The PIN Method (Where the Real Problem Lives)

The PIN method is what makes WPS dangerous. The router advertises an 8-digit PIN that devices can use to authenticate. The PIN is split into two halves: the first 4 digits and the last 4 digits. The router validates each half independently, which means an attacker only needs to brute-force two short PINs instead of one long one.

There are only 10,000 possible combinations for the first half and 10,000 for the second half. Combined with the last digit being a checksum, the total attack space is around 11,000 attempts. Modern cracking tools can try all of these in under 5 hours on a typical home router.

Once the PIN is cracked, the attacker receives the WPA2 passphrase and full network access. They do not need to be a security expert. Tools like Reaver and Bully automate the entire process and have been freely available for over a decade.

Why WPS Does Not Turn Off Automatically

WPS does not turn off automatically after a pairing session ends. The feature remains active on the router, and the PIN stays exposed. Some newer routers add a lockout after failed attempts, but many still allow unlimited tries. That is why disabling WPS on your router is the only reliable fix.

Why You Should Disable WPS on Your Router

Disabling WPS on your router is one of the highest-impact security changes you can make in under five minutes. The convenience the feature provides is small compared to the attack surface it opens.

The Brute-Force Attack Timeline Is Brutal

Independent security researchers have documented WPS PIN attacks that finish in under 4 hours against consumer routers. Older routers with no lockout policy can fall in under 2 hours. In 2026, this attack is still viable against millions of routers that ship with WPS enabled by default.

Reddit’s r/HomeNetworking community has long reached consensus that WPS should be disabled immediately. One user summed it up: “If X failed attempts, disable WPS until reboot” features help, but you should still turn it off. That matches advice from security researchers who have been flagging WPS since 2011.

Default-On Behavior Catches Users Off Guard

Most home users do not know WPS is enabled. The router ships with it on, the WPS button sits on the back panel, and the documentation rarely highlights it. I have asked dozens of friends and family members whether they knew WPS was active on their router, and almost none did.

Bell Canada Home Hub devices had a critical WPS vulnerability that was widely reported. The router manufacturers have been quietly disabling WPS by default on newer models since around 2018, but not all of them. Routers older than 5 years almost always still have WPS on.

Almost Nobody Actually Uses WPS

Here is the interesting part: in my experience, less than 5% of home users actively use WPS to connect devices. They either forget the feature exists, or they type the Wi-Fi password once and never worry about it again. So the security risk sits there for years, providing no real benefit.

WPS Does Not Protect a Strong Password

Even if you use a 25-character WPA2 password with symbols, the WPS PIN bypasses all of that. The attacker does not crack the password. They use the PIN to extract it. Disable WPS on your router and your strong password actually does what it is supposed to do.

How to Disable WPS on Your Router: Step-by-Step Process

Disabling WPS on your router takes between 3 and 10 minutes depending on your router brand. Below is the universal process, followed by brand-specific notes for the most common routers.

Step 1: Connect to Your Router’s Network

Make sure your device is connected to your router either over Wi-Fi or with an Ethernet cable. Disabling WPS will not kick you off immediately, but you want a stable connection during the change.

Step 2: Open the Router Admin Panel

Open a browser and type your router’s IP address. Most consumer routers use one of these addresses:

  • 192.168.1.1

  • 192.168.0.1

  • 192.168.1.254

  • 10.0.0.1

If none of those work, check the label on the bottom of your router. It usually lists the default gateway address.

Step 3: Log In With Your Admin Credentials

Enter your router’s admin username and password. If you have never changed them, the default is usually admin/admin or admin/password. The defaults are also on the sticker underneath the router. If you have changed them and forgotten, you will need to factory reset the router.

Step 4: Find the WPS Setting

Navigate to the Wireless settings, Security settings, or Advanced settings section. Look for any option labeled WPS, Wi-Fi Protected Setup, Push Button Connect, or PIN. Common router admin paths include:

  • Wireless > WPS

  • Advanced > Wireless Settings > WPS

  • Security > WPS

Step 5: Disable WPS and Save

Toggle the WPS option off, uncheck the box, or select Disable. Click Save, Apply, or OK. Your router may reboot, which takes 30 to 60 seconds. After the reboot, WPS is fully disabled.

For Netgear routers, the WPS setting is under Advanced > Advanced Setup > Wireless Settings. You can disable WPS entirely or keep push-button only. I recommend disabling both for maximum security.

For TP-Link routers, head to Wireless > Wireless Settings. The WPS option sits at the bottom of the page. Some TP-Link models call it “WPS Wizard” instead of “WPS.”

For Xfinity (Comcast) routers, sign in at 10.0.0.1 using the credentials on the sticker. Go to Gateway > Connection > Wi-Fi, then find and disable WPS. Some Xfinity firmware updates have removed the option entirely, in which case WPS is already off.

For AT&T routers, the path is usually Home Network > Wireless. Look for WPS and switch it off. If you do not see the option, the firmware may already have WPS disabled, which is good news.

What If Your Router Does Not Let You Disable WPS?

Some ISP-provided routers, especially older ones, do not expose a WPS toggle. The community workaround is to call the ISP and request a setting change, or to put the ISP router in modem-only mode and buy a separate router. The second option is what I recommend because you get full control over your wireless network security.

How to Verify WPS Is Actually Disabled?

After you disable WPS on your router, take 90 seconds to verify the change actually took effect. There is no point in doing the work if you are not sure it worked.

Check the Router Admin Panel

Log back into the admin panel and navigate to the same WPS settings page. The status should show Disabled, Off, or Unchecked. If it still shows Enabled, repeat the toggle and make sure you click Save.

Run a Network Scan

From a computer, run a Wi-Fi network scanner. Tools like Acrylic Wi-Fi (Windows) or NetSpot (macOS) show WPS information for nearby networks. After disabling WPS, your network should not show a WPS flag or PIN entry. If it still does, the setting did not save.

Try the Old PIN

Try to connect a device using the old WPS PIN. The connection should fail, and the router should not enter pairing mode. Both behaviors confirm that WPS is fully disabled.

Inspect Router Logs

Some routers keep a security log. Look for any WPS-related activity after your disable attempt. If you see nothing, the feature is off. If you see pairing attempts, the toggle did not apply.

Safer Alternatives to WPS for Connecting Devices

Disabling WPS does not mean you lose the ability to connect devices quickly. There are better, more secure alternatives available in 2026.

Use the Router’s Mobile App

Most modern routers ship with a companion app that handles device pairing. Netgear Nighthawk, TP-Link Tether, and Asus Router all let you tap a button to send Wi-Fi credentials to a new device over Bluetooth or a QR code. This is just as fast as WPS and far more secure.

Use QR Codes for Guest Access

Many routers now generate a QR code that guests can scan with their phone to join the network. The QR code encodes the password, so it is only shared with people you actually hand the code to. This is the modern version of WPS, and it solves the same convenience problem.

Use WPA3-Personal If Available

WPA3 replaces the shared password model with Simultaneous Authentication of Equals (SAE). Brute-force attacks against WPS-style PINs become impossible because there is no PIN to attack. If your router supports WPA3, switch to it and disable WPS.

Just Type the Password

On most modern devices, typing the Wi-Fi password takes 15 seconds. The original WPS use case, where you could not easily type a password, no longer applies. Smart TVs have on-screen keyboards, printers have screens, and phones have keypads. Manual password entry is the simplest secure alternative.

Consider a Separate IoT Network

Many routers support a guest network or a separate IoT VLAN. Put your smart bulbs, cameras, and printers on an isolated network. Even if one device gets compromised, the attacker cannot reach your main computers and phones. This is the gold standard for home network security.

FAQs

Should I turn off the router WPS?

Yes, you should turn off WPS on your router as soon as possible. The WPS PIN method can be brute-forced in under 5 hours by automated tools, giving attackers full access to your wireless network even with a strong password. The convenience benefit is small because most users do not actively use WPS.

Is it good to enable WPS in a router?

No, enabling WPS is not recommended in 2026. The PIN method exposes a brute-force attack surface that bypasses WPA2 and WPA3 encryption entirely. The push-button method is safer, but most modern routers and devices offer QR codes, mobile apps, and WPA3 that handle setup without the security trade-off.

Is WPS Wi-Fi good or bad?

WPS is bad for security and offers limited real-world convenience. The push-button method is mostly safe but can be triggered accidentally, while the PIN method has a documented brute-force vulnerability that security researchers have flagged since 2011. Most home users are better off disabling WPS and using a WPA2 or WPA3 password.

What happens if I accidentally press the WPS button on my router?

If you accidentally press the WPS button, your router enters pairing mode for about 1 to 2 minutes. Any WPS-compatible device within range can join your network without a password during that window. In most cases, no device will connect in time, but you should disable WPS entirely so accidental presses cannot expose your network.

Final Verdict: Should You Disable WPS on Your Router?

Yes, you should disable WPS on your router. The feature was a thoughtful idea in 2006, but the PIN brute-force vulnerability has been public for over a decade and remains trivial to exploit. The convenience is small, the risk is real, and the fix takes less than 5 minutes for almost any router.

After you disable WPS router-wide, switch to WPA3 if your hardware supports it, set a strong password, and consider putting IoT devices on a separate guest network. These three changes alone put your home network ahead of 90% of consumer routers in 2026. If you have family members or neighbors who never log into their router admin panel, share this guide with them. The WPS setting is the single most common security mistake on home networks, and it is the easiest to fix.

Leave a Comment