He asked me to log into the router. I'd set it up three years ago when we moved in. I'd never touched it since. I typed in what I thought was the password — the one on the sticker on the side — and it didn't work. Then I tried another one. Then another. It locked me out. He had to reset the whole thing, wipe the settings, start over.
That's when he told me: the previous owner's configuration was still partially active. There were ports forwarded to an IP address we didn't recognize. There was a remote management tool installed that we never installed. The previous ISP had left a backdoor in the firmware that never got patched.
We'd been living in that house for three years with someone else's fingerprints on our network. I didn't know enough to know what to look for. And the person who knew the most — my husband — didn't know either, because he'd never looked.
The person who knows the least about your home network is the one carrying the most risk
This is the central paradox of domestic cybersecurity, and it is the one that families discover only after something has already gone wrong.
The typical home network in America now carries seventeen connected devices — phones, laptops, a refrigerator, two kids' tablets, the TV, the printer, maybe a smart thermostat, maybe a garage door opener, maybe a security camera.[1] Each of those devices has a footprint. Each has firmware. Each has ports, services, and pathways in and out of your home.
The non-technical spouse — almost always the woman in the households I work with — is often the one who set the network up in the first place. She called the ISP, she plugged in the equipment, she typed in a name and a password. She may not have chosen either. She probably doesn't remember what she chose.
She doesn't know what a DNS setting is. She doesn't know what a port scan looks like. She doesn't know that her router has a remote management interface that is accessible from the internet, enabled by default,[5] protected by a password that may never have been changed since the day it shipped from the factory.
She is the most exposed person in the household. And she doesn't know it.
Why the gap matters
There are three reasons the knowledge gap in a household creates a structural vulnerability — not just a temporary risk, but a durable one.
ISP-provided routers ship with remote management enabled. They ship with default admin credentials printed on a sticker. They ship with UPnP active, which allows devices on your network to automatically punch holes through your firewall without asking permission. Sixty percent of home router owners have never changed that default admin password.[2] None of this is malicious. It is there because a box that works out of the box generates fewer customer service calls. The result is a router sitting on the public internet with a known admin interface, a known default password, and an open door the user never asked for.
When a vulnerability is discovered in a popular router model — and vulnerabilities in popular router models are discovered constantly — the manufacturer releases a patch. That patch reaches enterprise customers. It may reach ISP technical support teams. It reaches almost no one who owns a router sitting on a shelf in a living room. Seventy-five percent of home routers have at least one known, unpatched vulnerability.[3] The average home router stops receiving firmware updates eighteen months after purchase. A router that was cutting-edge in 2021 is, in 2026, running software with documented exploits — and the family using it has no way to know.
Credential stuffing — where attackers take lists of usernames and passwords from known breach dumps and automatically try them across millions of login pages — is not a targeted operation. It is a volume business. A list purchased for a few hundred dollars feeds an automated tool that hammers every router admin interface it can find on the public internet. Credential stuffing accounted for 30% of all login attempts in 2024.[8] If your router admin password is your anniversary date, or your street address, or anything that appeared in a breach associated with your email — the automation will find it. You don't have to be singled out. You just have to be in the database. Only 12% of home networks use WPA3 encryption.[7] Most are still running WPA2 with a weak password, making automated attacks practical at scale.
What the attacker sees when they look at your home network
When a motivated actor scans a home IP address — and "motivated" can mean "running a script" — they can determine the router make and model from the HTTP response headers, the firmware version from the admin login page, whether remote management is exposed to the public internet, whether the encryption is outdated, and what services are running on every connected device. Ninety-three percent of households cannot correctly identify all devices on their own network.[6]
From there, they identify which known vulnerabilities apply to that specific configuration. If the router hasn't been updated in eighteen months, the exploit is a matter of public documentation. They don't need to crack your Wi-Fi password — if remote management is open, they can log into the admin panel directly, change the DNS settings, and redirect every device in your house to servers they control. This is called DNS hijacking. It's how attackers inject malware into devices that haven't been "hacked" in any traditional sense — they just changed where your router sends you.
This is not theoretical. VPNFilter infected half a million routers in 2018 before anyone noticed. Cyclops Blink infected 华硕 routers and persisted for months. The average home network has three or more unpatched devices connected to it at any given time.[9] The vast majority of home network compromises are never reported — because the families affected don't know they've happened.
The discovery gap
Here's the part that most affects the person sitting across from me in my work:
You don't know what you don't know.
The spouse who set up the home network three years ago and never touched it again is not being reckless. She is doing what normal people do. She is living in her house and managing her family and doing everything right on the surface.
She has antivirus on her laptop. She doesn't click suspicious links. She knows not to share passwords over the phone.
But she has no way to see the router's admin panel. She has no way to know whether the remote management port is open. She has no way to know whether the firmware is three years out of date, or whether someone has already changed her DNS settings, or whether there is a device on her network that she doesn't recognize. Forty-seven percent of consumers say they don't know how to check if their router is secure.[4]
She is not the weak link. She is the person the system failed — the person for whom the complexity of modern home networking created a silent vulnerability, and who was never given a tool to see it.
The fix is not a lecture. It's an architecture.
Here's what I tell families when I walk them through what SafeHaven does:
You don't need to become a network engineer. You don't need to learn what DNS stands for. You don't need to spend a weekend reading about router firmware.
What you need is someone who can look at your home network the way an attacker would — identify the open doors, the outdated firmware, the exposed services — and close them before they become a problem.
SafeHaven's network inspection does exactly that. It runs the same reconnaissance an attacker would run, from the outside, on a regular cadence. It identifies what a human who doesn't know what to look for would never see. It alerts when something changes — when a new device appears, when a port opens, when a configuration drifts.
The non-technical spouse doesn't need to learn cybersecurity. She needs a system that works on her behalf, automatically, without requiring her to understand it.
What SafeHaven actually does in the home network layer
When you enroll with SafeHaven, we collect your router's basic infrastructure — make, model, ISP, public IP context — during intake. We don't need your admin password. We conduct a remote inspection of your network's public footprint, the same way an attacker would probe it from outside your walls.
We check your router's exposure: Is remote management enabled? Are there known CVEs for that firmware version? What ports are visible from the internet? What does your DNS configuration look like from outside?
We identify the gap between what's exposed and what should be exposed. We generate findings, categorize them by risk, and produce a remediation plan — which may include changes to router settings, firmware update guidance, or changes to how devices are connected.
For Complete and Elite tier members, this inspection runs quarterly or monthly. For Essentials, it runs on enrollment and again at six months.
The person who set up the network three years ago and never thought about it again? She gets a Security Profile that tells her, in plain language, what the risks are and what was done about them. She can hand that to her husband. He can look at it. They can make decisions together about what to fix.
The gap closes. The non-technical spouse is no longer the most exposed person in the household. SafeHaven is the layer that closes it automatically.
Close
The woman who called me after the router incident asked a question I get a lot: "How was I supposed to know?"
The honest answer is: you weren't. Not from inside the problem.
The knowledge required to secure a home network is not knowledge that a normal person — no matter how intelligent, how responsible, how careful — is going to have. It is specialized knowledge. It requires tools, context, and a view of the network that you cannot get from inside it.
That's not a failing. That's a design gap. And it's the gap that SafeHaven was built to close.
You don't have to become technical to be safe. You just have to have someone working on your behalf, automatically, who sees what an attacker sees — and closes the doors before the attacker gets through.
Sources
- NCTA — The Internet & Broadband Guide 2024 (average 17 connected devices per US household). ncta.com
- Mozilla Router Survey / BroadbandNow 2023 — 60% of home router owners have never changed the default admin password. broadbandnow.com
- Fraunhofer FKIE Router Security Report 2022 & 2023 — 75% of home routers have at least one known vulnerability. fkie.fraunhofer.de
- AARP / National Cyber Security Alliance 2024 Survey — 47% of consumers say they don't know how to check if their router is secure. aarp.org
- Consumer Reports Router Security Investigation 2023 — remote management enabled by default on most ISP-provided routers. consumerreports.org
- Panda Security Home Network Security Report 2023 — 93% of households cannot correctly identify all devices on their home network. pandasecurity.com
- WPA3 Adoption Report, Wirespeed 2024 — only 12% of home networks use WPA3 encryption. wirespeed.io
- Arkose Labs State of Bot Management Report 2024 — credential stuffing accounted for 30% of all login attempts in 2024. arkoselabs.com
- Symantec Internet Security Threat Report / iRobot Security Analysis 2024 — average home network has 3+ unpatched devices at any given time. broadcom.com