The reset button is the most popular answer to a lost admin password, and usually the wrong one. It works the way a bulldozer works. On a switch carrying six months of VLAN and port config, or a firewall with a policy set nobody documented, it turns a ten-minute problem into a two-day one. There are four things worth trying first, and on a good number of devices one of them gets you in with the configuration untouched.
What follows is a ladder. Each rung costs more than the one above it, and the trick is knowing which rung your device starts on, because the wrong first move destroys what the right move would have saved.
- Rungs 1 and 2
- Change nothing on the device. Try these on anything.
- Rung 3
- Factory reset. Cheap on consumer kit, expensive on anything configured.
- Rung 4
- Console and bootloader. Most often skipped, most often keeps the config.
- Rung 5
- Vendor challenge-response. Slow, needs proof of ownership, only exists if left enabled.
- Before anything
- Photograph the label. Model, hardware revision, serial and MAC all matter later.
Before you touch anything
Identify the hardware properly — not the brand, but the model, the hardware revision and roughly which firmware era it is on. A Netgear WNDR3700 v1 and a v4 are different devices wearing the same name, and the revision sits on the label as Ver 2.1 or v4 or Rev A. Rungs 4 and 5 also need hands on the unit, so if it is three hundred miles away in a cabinet, decide now who is driving.
Then the fork the whole ladder turns on: is the running configuration worth more than the time to rebuild it? On a home router you were about to reconfigure anyway, no. On a distribution switch or a firewall, emphatically yes, and a reset drops from third option to last resort.
Rung 1 — Read the label, and read all of it
The universal default is dying. California has required a unique per-device password or forced setup since 2020, and the UK banned universal default passwords on consumer connectable products in April 2024, so anything recent probably carries a credential printed on the unit itself.
Labels hide: under rubber feet, behind the wall-mount bracket, inside the battery compartment, on the power supply rather than the device, and on servers a pull-out plastic tag at the front of the chassis. That tag is where Dell prints the unique iDRAC password on current PowerEdge generations; HPE puts the iLO password on the pull-tab serial label. Some vendors print it on a card in the box instead.
Then read the whole label, not the first password-shaped string on it. Consumer routers commonly carry three secrets: the Wi-Fi passphrase, the admin password and the WPS PIN, and typing the Wi-Fi key into the admin login is probably the commonest reason someone concludes their password was changed. If there is a QR code, scan it and read the raw decoded text instead of letting your phone open the URL — the credential is often sitting in a query parameter.
When the label lies
On ISP-supplied routers and ONTs the printed password may have been rotated remotely after installation over the provider’s TR-069 channel, which makes the label a historical document. If it is rejected on a unit you did not buy yourself, stop climbing and ring the provider. They hold the only working account, and a reset leaves you with a device that still needs provisioning you cannot perform.
Rung 2 — The documented default for that exact hardware revision
With no per-device label, the device is old enough to have a shared default and the only question is which one. The failure mode is the near miss: right brand, right model family, wrong revision. Defaults change between hardware revisions and firmware generations, so a unit that shipped with admin/password may have moved to a per-device credential during an update it took three years ago in someone else’s house.
Work from the exact string on the label. Our A–Z index of default credentials cites the vendor document each record came from, which matters precisely because so many circulating lists have drifted. If the device is Cisco, the Cisco defaults page is split by product line — Small Business, IOS and the acquired lines never shared a convention.
Blank counts as a value: plenty of devices want admin with an empty password field, or an empty username with password admin. Protocols differ too, because the web UI, the CLI and SNMP are separately configured on most enterprise gear, so a credential rejected over HTTPS may be accepted over SSH. And lockouts mean that after a handful of failures you are no longer testing passwords at all — if attempts three through eight failed instantly and identically, wait half an hour and try the first one again.
Rung 3 — The reset you have not actually performed yet
Most reports of “I factory reset it and the default still does not work” are reports of a reset that never happened.
- Confirm it is the reset button. Recessed pinholes are not all resets — on consumer routers the neighbour is often WPS. HP and Aruba AOS-S switches have both Reset and Clear: pressed together they restore factory defaults, but Clear alone only wipes the local usernames and passwords and leaves the configuration intact.
- Use a tool that actually depresses it. A paperclip slightly too thick bottoms out on the case before it reaches the switch. You want a distinct click, or at least a feeling of travel.
- Hold it long enough, with the power on. Ten seconds is the usual minimum, thirty is safer, and most devices want to be powered up and fully booted throughout. A minority want it held while power is applied — the Cisco Catalyst Mode button and several bootloader sequences — and that is a different action, not a longer version of the same one.
- Watch for the acknowledgement. LEDs cycling, all of them flashing at once, the unit rebooting. If nothing happened, nothing happened.
- Then wait. Two or three minutes to come back up, on an address that has moved back to the factory subnet. Renew your DHCP lease before deciding the device is dead.
Some devices stage the reset deliberately, and Synology is the clearest case. Hold RESET until you hear a single beep, roughly four seconds, then release: that is the mode 1 reset, which clears the administrator password and puts the network settings back to DHCP while leaving users, shared folders and data alone. Hold for a beep, release, then hold again until three beeps and you have asked for a mode 2, which prepares the unit for a clean DSM reinstall. You want the first.
Controller-managed wireless is the other place a reset is cheap. An adopted UniFi access point takes its SSH credentials from the controller’s site settings rather than holding its own, so if the controller is alive you change the password there and never touch the hardware. An orphaned AP resets to ubnt/ubnt, you re-adopt it, and the controller pushes the configuration back. Nothing is lost because it never lived on the AP.
Do not interrupt the write
The minute or two after a reset is when the device rewrites its configuration partition. Pulling power there is one of the few reliable ways to brick consumer hardware. Leave it alone until it settles, even if the LEDs look wrong.
A reset also erases less than people assume — certificates, stored keys, logs, and on plenty of devices the firmware-level account you were locked out of. See what a factory reset does not erase; if you have already reset and are still refused, the default password not working after a reset works through the causes.
Rung 4 — Console access and the bootloader
This is the rung that gets skipped, and on managed infrastructure it is usually the right answer. A serial console reaches the device before the network stack, before the login lockout and — critically — before the configuration is loaded, which is what lets you in without destroying it.
The port is an RJ45 socket, a USB mini-B or micro-B, a 3.5 mm jack on some Cisco and Aruba gear, or bare UART pads inside consumer hardware never meant to have a console. Most enterprise kit runs 9600 8N1; embedded Linux devices frequently run 115200. Getting a serial console on a device covers cabling and adaptors. What happens next is vendor-specific, and this is exactly where guessing goes badly. Four worth knowing.
Cisco IOS routers
Send a break within the first sixty seconds of boot to reach rommon, set confreg 0x2142 so the router ignores its startup configuration, then reset. It boots clean. Now the part that matters: from enable mode run copy startup-config running-config to pull your real configuration back into memory, change the enable secret and the local users, set config-register 0x2102 and save. Interfaces will still be shut, so no shutdown them.
The one command that destroys the config
Do not type copy running-config startup-config before you have copied startup into running. At that moment the running configuration is the empty default, and you overwrite the very thing you broke into the router to save. The direction matters more than anything else here.
Cisco Catalyst fixed-configuration switches
Hold the Mode button while reconnecting power until the console shows the switch has stopped, roughly half a minute. At the switch: prompt run flash_init, move the config aside with rename flash:config.text flash:config.old, then boot. Decline the setup dialog, rename the file back, and load it with copy flash:config.text system:running-config before changing the password and saving.
Aruba CX switches
Interrupt the boot to reach the Service OS console and log in as admin, which by default has no Service OS password. At the SVOS> prompt the command is simply password, then boot. The configuration survives. Service OS also exposes a zeroize login that factory-defaults the switch, which is the thing you are avoiding.
Juniper devices running Junos
Interrupt the loader, run boot -s for single-user mode, and when it asks for the pathname of a shell type recovery instead. That drops you into a CLI where you can configure, run set system root-authentication plain-text-password and commit. Configuration intact.
Check whether rung 4 was switched off
Cisco’s no service password-recovery is the one to watch. With it set, breaking into ROMMON still works, but the device erases the startup configuration as it does so — by design, to stop exactly the procedure above. The boot output tells you. HP and Aruba AOS-S have the equivalent in front-panel-security password-clear disable, which turns the Clear button into a no-op.
Switches carry enough of their own quirks that we treat them separately in managed switch password recovery.
Rung 5 — Vendor challenge-response recovery
Some vendors run a real recovery channel: you hand over an identifier bound to that specific unit and get back an unlock that works only on that unit, and only for a short window. Slower than everything above, but it preserves the configuration, and it exists so the vendor need not ship a universal backdoor.
HPE and Aruba AOS-S switches
Password recovery is on by default. Give Networking Support the switch MAC address, printed at the upper right of the front panel, and they generate a one-time alternate password that gets you in without a factory reset. If someone has previously run no password-recovery, that route is closed and Reset plus Clear is all that remains.
Hikvision cameras and recorders
Run SADP on the same LAN, select the device, click Forgot Password and then Export, which writes a device key file. Send it to Hikvision support or your distributor with a photograph of the label showing model and serial, and they return a key file you import in SADP to set a new password. It is time-limited — a day or so, not a week — so be in front of the device when it arrives. Use a current SADP build; older releases cannot read the newer key format.
Dahua recorders and cameras
The local GUI shows a QR code on the forgotten-password screen; scan it in the DMSS app and a security code goes to the email address bound to the recorder. The catch is the binding. If nobody entered a reserved email at initial setup there is nowhere to send it, and the route does not exist for that unit. Worth checking on every recorder you commission: thirty seconds then, impossible later.
Expect to prove ownership with invoices, serials and a photo of the unit in situ, and expect hours or a day rather than minutes. IP camera and NVR password recovery goes through these flows in detail.
Do not feed your serial number to a password generator site
Search results for these platforms are thick with tools promising an instant reset code from a serial number or a date. A few rest on broken legacy algorithms the vendors patched years ago; most are harvesting identifiers. You are handing a stranger the serial of a camera system and telling them you cannot get into it.
When a device genuinely cannot be recovered
Sometimes there is no rung 6, and it is better to know that in the first hour than the third day. On almost all of these the hardware is fine. It is the configuration that is gone.
MikroTik RouterOS
Your options are the reset button or a Netinstall, and both wipe the configuration. No console trick survives on current releases. The licence and the RouterBOOT settings come through; nothing else does.
FortiGate firewalls
Fortinet removed the maintainer console account in FortiOS 7.2.4, and the release notes are blunt about the consequence: lose the password and you need physical access and a TFTP firmware restore, which clears the configuration. On older firmware it still works — console in and, within roughly fourteen seconds of a hard power-cycle, log in as maintainer with password bcpb followed by the serial number in uppercase. Plenty of administrators had already switched it off with set admin-maintainer disable. An unencrypted backup is the closest thing to a save: edit the set password ENC line of a super_admin account to a plaintext value and restore it after the reload.
The quieter dead ends
Verified boot with no serviceable bootloader, which covers most recent consumer gateways and effectively all ISP-locked ONTs: the bootloader refuses modified arguments and the provider holds the only administrative account. Data encrypted with a key derived from the password, where getting back into the NAS still does not unlock the volume. And devices whose manufacturer no longer exists, because challenge-response works only while somebody runs the server that answers the challenge — for a growing number of white-label cameras, that machine was switched off years ago.
On anything holding data — an NVR, a NAS — get the disks out and read them on another machine before you do anything else to the chassis. Recovering the footage and rebuilding the appliance are two separate jobs, and the order is not optional.
Where each device class starts on the ladder
| Device class | Start at | Why |
|---|---|---|
| Home routers and cable gateways | Rung 1 | Label password on anything recent; config is cheap to rebuild |
| ISP fibre ONTs and managed modems | Rung 1, then stop | A reset leaves you unprovisioned |
| Managed switches | Rung 4 | Clear button and Service OS preserve the config |
| Enterprise routers | Rung 4 | ROMMON and the config register keep the startup config |
| Firewalls and UTM appliances | Rung 4, then 5 | Console recovery where it survives, else a TFTP reload |
| Controller-managed wireless APs | Rung 3 | Reset and re-adopt costs minutes |
| Standalone wireless APs | Rung 2, then 4 | Documented defaults common, UART pads usually present |
| IP cameras | Rung 5 | Challenge-response is the designed path |
| NVRs and DVRs | Rung 5 | Pull the disks first if footage matters |
| NAS appliances | Rung 3 | Staged resets exist to spare the volumes |
| Server BMCs (iDRAC, iLO, IPMI) | Rung 1 | Per-unit password on the pull-out tag |
| Network printers and MFPs | Rung 1, then 3 | PIN on the label, then a cold reset from the front panel |
| VoIP handsets | Rung 2 | Provisioning may reassert the admin code anyway |
| UPS and PDU network cards | Rung 3 | Resets the management card, not the UPS |
| KVMs and serial console servers | Rung 2, then 4 | If this is what locked you out, rung 4 is what you have lost |
| Industrial and building control gear | Rung 5 | Never reset a controller that is running a process |
What to do in the first ten minutes after you are back in
You are in, the adrenaline is fading, and this is the only moment you will ever be motivated enough to do any of this.
- Export the configuration before anything else. Before the password change, before any reboot. If the session drops now you are back at the top of the ladder.
- Set a real password where the next person will look. The team password manager, with the hostname and management address in the record. Tape on the chassis is not a system, and neither is one administrator’s memory — which is how this started.
- Record the identifiers in the same entry. Model, hardware revision, firmware, serial, MAC. Rung 5 needs the serial or the MAC, and the worst time to hunt for them is when the device is refusing to talk to you.
- Bind the recovery channel while you can. Set the reserved email on the recorder. Confirm
password-recoveryis still enabled on the switch and the Clear button has not been disabled. Decide deliberately whether console recovery is on or off rather than discovering the answer later. - Write down which rung worked. One line in the asset record. Next time somebody is standing in front of the same model with the same problem, they start at rung 4 instead of reaching for a paperclip.



