Add a password

Default password not working after a factory reset: eight causes, and how to tell them apart

The default password still won't work

You held the pin in, the lights cycled, the unit came back up — and the credential printed on the label, or listed on our page for that model, is still refused. The credential is usually not the problem. Something between the reset and the login form is.

Eight things cause this, and each leaves a different fingerprint. That matters, because the usual advice — reset it again — only fixes one of them.

Check this first
Has the Wi-Fi network name reverted to the one on the label?
Typical reset hold
7 to 10 seconds, powered and fully booted
Commonest on ISP kit
The operator’s server reconfiguring the box a minute after boot
Post-reset login failures, by what you actually see
Symptom Most likely cause
Your old SSID still broadcasting; your old password still works 1 — the reset didn’t take
Model matches the listing, but the interface looks nothing like it 2 — different hardware revision
Internet returns on its own in a minute; password still refused 3 — ISP provisioning
No password field at all — a setup wizard instead 4 — forced credential creation
Long random string on the sticker; documented passwords refused 5 — per-unit password
Something answers, but it isn’t the device you reset 6 — wrong interface
Short, simple password refused instantly and consistently 7 — mistyped without knowing it
Factory-fresh for a minute, then the old settings reappear 8 — config restored on boot
Advertisement

1. The reset didn’t complete

The press has to be seen by firmware that is already running. If the unit was mid-boot, or the pin never reached the switch at the back of a deep recess, or you let go two seconds early, nothing happened. Reset switches on cheap consumer kit fail mechanically too — the plunger sticks and the contact never closes.

Netgear’s wording for most of its routers is to hold the Restore Factory Settings button with a straightened paper clip until the Power LED blinks, which is around seven seconds. TP-Link’s figure is nearer ten. The number matters less than the acknowledgement: on most devices something on the front panel changes state while you are still holding the button. If nothing does, the press is not registering, and another minute won’t help.

The reliable check afterwards is the wireless network name. A device that really went back to defaults broadcasts the factory SSID — usually the one on the label, often with the last few MAC digits appended. If your own SSID is still there, you have a live configuration and a failed reset, not a credential problem.

Skip the 30-30-30

Thirty seconds holding reset, thirty more with the power pulled and the button still held, thirty after power returns. That was real advice around 2006 for clearing NVRAM on Broadcom-based routers before flashing third-party firmware, on hardware where the bootloader itself watched the button. Current kit reads the button from the running system, so the powered-off two-thirds of the ritual does nothing at all — and repeatedly interrupting boot is a good way to land in the bootloader’s TFTP recovery mode instead of a clean device. OpenWrt’s own reset is failsafe mode and firstboot, not a stopwatch.

2. That model has more than one hardware revision

Vendors keep a model name in the catalogue for a decade and change everything underneath it. The same badge can cover several chipsets, three web interfaces and two default addresses. TP-Link prints the revision on the underside label as Ver: 3.0 or V3, beside the model number; most manufacturers do something similar, sometimes as a suffix buried in the serial.

Across revisions of one TP-Link model you can find an early unit at 192.168.0.1 answering to admin / admin, and a later one that refuses every password because its firmware now makes you create one at tplinkwifi.net. Neither listing is wrong. They describe different hardware.

So take the revision off the label before you search, and search on model plus revision. Our TP-Link page splits entries by revision where the defaults differ, and the A–Z manufacturer index is organised the same way. The same discipline matters for firmware — an image built for the wrong revision is one of the few reliable ways to brick a router outright.

Advertisement

3. ISP or integrator firmware replaced the default

The giveaway here is timing. You reset the box, the internet comes back within a minute or two without you entering a single setting, and the manufacturer’s password is still refused. Sometimes the documented password works for a short window immediately after boot and then stops.

That is remote management doing its job. Operator-supplied equipment is built so that a reset restores the operator’s provisioning profile rather than the chipset vendor’s: the WAN parameters and the address of the auto-configuration server survive, the box checks in over TR-069 as soon as the line is up, and the server pushes the operator’s configuration back down, administrative account included. The reset worked perfectly. The configuration was put back thirty seconds later by someone else’s machine.

Plenty of ISP hardware is also the vendor’s silicon in the vendor’s case running firmware the vendor did not write — same board as the retail model, entirely different credential scheme. The password is then per-account and comes from the ISP: the welcome letter, the account portal, or a card the ISP supplied with the box.

Buy yourself a window

Unplug the WAN — the fibre, coax or DSL lead, not just the LAN side — before you press reset. The box comes up unmanaged and stays that way until it can reach the provisioning server, which gives you time to get in and look at what is configured. Reconnect when you are done.

4. The device makes you create a password instead

If the first page after a reset is a setup wizard with a “create password” field and no password prompt at all, there is no default to get wrong. That is now the norm on new consumer hardware, and it is law rather than fashion: California’s connected-device statute has required either a unique per-device password or forced credential creation at first use since 1 January 2020, and the UK’s Product Security and Telecommunications Infrastructure regime has applied the same rule to anything supplied in Britain since 29 April 2024.

The corollary is useful for diagnosis. On a device of that generation, a login form with a password field means the device is not in a factory state — go back to cause 1, or on to cause 8. The shift is covered in universal versus unique default passwords.

5. The password is per-unit, and it’s on the label

Between a universal default and a forced wizard sits a password generated at the factory, printed on the unit, and restored by a reset. AVM has done this on the FRITZ!Box for years: the interface password is unique to each box, printed on the underside and on the supplied service card, with no generic default to fall back on. Most UK ISP gateways do the same, usually on a pull-out card, and a good deal of retail kit sold since the 2020 rules has followed.

This one trips people up backwards. The reset did work, and it restored the printed password, so the label is authoritative again. If you were typing the vendor’s historical universal default, you were typing the wrong thing both before and after.

The other trap is that the sticker carries at least two distinct secrets, and they are not interchangeable.

Schematic of a router underside label showing the hardware revision, the Wi-Fi key and the admin password as three separate fields UNDERSIDE LABEL

Model

Hardware Ver.

S/N and MAC

Wi-Fi network (SSID)

Wi-Fi password / key

Admin / router password

Decides which default applies at all (cause 2)

Gets a client onto the radio. Not a login.

Gets you into the management interface.
Three fields, three different jobs. The network key and the admin password sit a couple of lines apart on most labels and are routinely swapped.

6. You’re logged into the wrong box

Most sites have more than one device answering on port 80. A DOCSIS cable modem hosts a diagnostics page at 192.168.100.1 and keeps hosting it even when bridged behind your own router — that page belongs to the modem, not the router you just reset. An ONT, an ISP gateway in front of your kit, an access point double-NATed behind it, a managed switch on its own VLAN: each has its own credentials, and resetting the one you can reach does nothing for the one rejecting you. Read the header of whatever page answered — model name, firmware version, WAN status — before you type anything into it. That is usually enough to say which box you have actually reached.

The same confusion happens on a single device, between management planes. A factory-reset UniFi device answers SSH as ubnt / ubnt while it sits pending adoption; the moment a controller adopts it those are replaced by whatever the controller has under Device Authentication, and the factory default is gone though the hardware never changed. On fully cloud-managed kit — eero, Google’s Wi-Fi products — there is no local login to get wrong at all. The account is the credential.

7. Caps, keyboard layout and the pipe character

Worth ruling out early, because it costs nothing and the symptom is distinctive: a short, simple password refused instantly, every time, with no intermittency.

  • Caps Lock, obviously. Less obviously, a phone or tablet keyboard capitalising the first letter and appending a space when it autocompletes.
  • Keyboard layout. UK and US layouts disagree about characters that turn up in defaults constantly. On a UK layout Shift+2 gives " and @ lives on Shift+apostrophe; on US it is the other way round. # has its own key on UK boards and is Shift+3 on US. The backslash and pipe key sits left of Z on an ISO keyboard and above Enter on ANSI. If the OS layout doesn’t match the keys in front of you, a | in a default silently becomes something else.
  • Serial consoles, IP KVMs and out-of-band cards are generally locked to a US layout whatever keyboard is plugged into them.
  • Trailing whitespace copied out of a PDF or a table cell. Some login forms trim it. Most do not.
  • Zero against capital O, digit one against lowercase L, in a condensed font on a small sticker.

Type it into the browser’s address bar first, where you can see it, then copy it into the field. That catches every item on this list in one go.

8. Something puts the old config back on boot

If the device comes up factory-fresh and then, a minute later, the old settings are back — the SSID reverts to the factory one, then changes again — something is restoring a saved configuration.

A controller is the usual culprit in managed environments. A UniFi or Omada device still cabled to the network and still listed in the controller’s inventory gets re-adopted and re-provisioned automatically, password included. Forget the device in the controller, or take it off that network, before you reset it. Vendor mobile apps do the same thing more politely, offering to restore a cloud backup during setup — tap through and you restore the configuration you were trying to clear.

Enterprise gear behaves differently again, because there is often no reset button at all. On Cisco IOS the configuration lives in NVRAM as the startup-config and loads at every boot, so recovery means telling the device to ignore it. Break into ROMMON during boot, set the configuration register to skip NVRAM, then pull the configuration in by hand once you have enable access:

rommon 1 > confreg 0x2142
rommon 2 > reset

Router> enable
Router# copy startup-config running-config
Router# configure terminal
Router(config)# enable secret <new-secret>
Router(config)# config-register 0x2102
Router(config)# end
Router# write memory

Two things bite people here. Skip the config-register 0x2102 and every later reboot ignores the saved configuration, which looks exactly like a device that keeps resetting itself. And do not issue write before you have copied the startup-config into the running-config, or you overwrite the configuration you were trying to recover with an empty one. Our Cisco page lists the console and enable defaults that apply once you are back in.

Dual-image devices can also fall back to the second firmware partition after a failed boot, complete with whatever configuration was stored alongside it — which looks like a reset that half worked. A reset clears less than most people assume in general; what a factory reset does not erase covers the certificates, provisioning records and bootloader settings that survive one.

When none of the eight fit

At that point you have stopped diagnosing and started recovering, and the tools change: a serial console on the board’s UART header, a TFTP recovery image, a vendor bootloader mode, an RMA. Those are set out in order of increasing pain in the locked-out device recovery ladder. Before you get there, make one more pass at the manufacturer index with the hardware revision in hand — a surprising share of these end at cause 2.

Advertisement
Facebook
Twitter
LinkedIn
Email
WhatsApp

MORE FROM ROUTERPASSWORDS.COM