Add a password

Universal or unique? The four kinds of default password

The four kinds of default password

Ask what the default password is for a given device and you get one of four kinds of answer, and only one of them is a password anybody can look up. The other three depend on a sticker, on a setup wizard you have not run yet, or on nothing at all. Working out which of the four you are holding takes about ten seconds, and it saves you from typing admin into a box that was never going to accept it.

The four regimes
Fixed universal, per-unit factory, set at first use, none
Lookup helps
Only with fixed universal defaults
Strongest tell
A random-looking string on the label means per-unit
After a factory reset
Per-unit devices return to the original label value, not a fresh one
Rough dividing line
Kit designed since about 2016 is far less likely to be fixed-universal

Four credential regimes

These are not marketing categories. They describe where the secret physically sits before you ever touch the device, and that determines what you can do about it.

1. Fixed universal default

One credential pair compiled into the firmware, identical on every unit of that model and frequently across a vendor’s whole catalogue. admin/admin, admin with the password field left empty, admin/password on a long run of older Netgear models, root/calvin on legacy Dell iDRAC controllers. The credential is knowable without ever seeing the hardware, which is why a reference index can exist at all — our A–Z of confirmed defaults documents this regime almost exclusively, because it is the only one a lookup table can represent.

These have not vanished. Anything designed before roughly 2016 and still racked and running is a candidate, and industrial controllers and budget DVRs remain full of them.

2. Per-unit factory password

The device leaves the factory with a working password unique to that individual unit, generated during manufacture and printed on it. Nobody can tell you what yours is. Most ISP-supplied hubs work this way, as do current server management controllers: Dell ships every PowerEdge with a randomly generated iDRAC password on the pull-out service tag at the front of the chassis, and HPE prints the iLO password on a tag attached to the server itself.

Dell also illustrates how muddy this gets, because buyers can order servers with the legacy calvin password instead of the unique one. Same model, same generation, two different regimes depending on a line on the purchase order. Regime is a property of the unit in front of you, not of the model name.

3. Set at first use

No credential exists until you create one. The device boots, refuses to do anything useful, and hands you a password field to fill in. Hikvision cameras and recorders ship in an “inactive” state — the unit will not stream, record or answer the client until it has been activated with a password you choose, and the old 12345 is long gone from current firmware. Most current consumer routers behave the same way, refusing to route until the setup wizard has taken a new admin password off you.

Do not assume it from the brand name, though. TP-Link still ships kit with admin/admin on the label alongside models that demand you invent a password, sometimes within the same product line. Where the regime does apply, asking for the default is a category error: there isn’t one, and the absence is deliberate.

4. None

No credential, and none demanded. The management interface answers to anyone who can reach it. MikroTik RouterBOARDs shipped for years with the username admin and a genuinely empty password, which is why they remain one of the most-looked-up entries on any defaults list. Newer MikroTik units carry a unique factory password on the sticker or the packaging, which moves them into regime 2. Plenty of legacy switches and industrial gear still sit here.

The four regimes compared
Regime Where the credential lives Can you look it up? Where you still meet it
Fixed universal Firmware, identical on every unit Yes Pre-2016 designs, industrial kit, budget DVRs
Per-unit factory Printed on the device at manufacture No — only the label knows ISP hubs, current consumer routers, server BMCs
Set at first use Nowhere, until you create it No — there is nothing to look up Current routers, IP cameras and NVRs
None Nowhere. Access is unauthenticated Not applicable Legacy switches, older MikroTik, industrial controllers
Decision tree for identifying which default-password regime a device uses Read the device label no password shown password shown

Open the LAN IP in a browser Told to create a password? yes no prompt SET AT FIRST USE NONE (wide open)

Is the value a common word — admin, password, 1234, blank? yes no FIXED UNIVERSAL PER-UNIT

Four outcomes, two questions. The left branch needs the device powered up; the right branch you can answer with the unit still in the box.

One case the tree does not cover: if opening the LAN address gives you an ordinary login prompt and the sticker showed nothing, the credential exists but lives somewhere other than the device. Check the carton and the quick-start leaflet before concluding it is a universal default — recent MikroTik units in particular ship the unique password on the box rather than the unit.

Reading the label

The sticker is the primary evidence, and more structured than it looks. Vendors use a reasonably consistent vocabulary, and the field names matter more than the values.

Anything named Admin password, Settings password, Management password, Device password or Router password is a regime 1 or regime 2 credential for the management interface. Anything named Wireless key, Network key, WPA key, Wi-Fi password or printed immediately below an SSID is the radio passphrase, and it is a different secret entirely.

Once you have found the admin field, look at the shape of the value rather than reading it. A pronounceable dictionary word, a four-digit number, or nothing at all puts you in regime 1, and the value will be in a defaults index. A mixed-case alphanumeric string of eight to twelve characters, or three concatenated dictionary words, was generated for your unit alone. Some vendors derive it from the serial number, which is weak — UK regulations now prohibit deriving a password from a product identifier unless it goes through encryption or a keyed hash — but it is still per-unit, and no lookup will give it to you.

Schematic of a router base label showing which printed field is the admin password Model AC1900-XYZ S/N 4K21A00123456 MAC A4:2B:B0:11:22:33 Wi-Fi name HUB-47F2 Network key braveoceanlamp4 Admin password Xk7#mQ2p WPS PIN 12345670 QR

Joins devices to the radio. Will not log you in anywhere. The management login. This is what 192.168.1.1 wants. Eight digits, for push-button pairing. Not a password.
A composite label — the values are invented, the field names are not. The QR code on a real sticker almost always encodes the Wi-Fi join string, not the admin credential.

A few things on labels are routinely mistaken for the admin password and are not. The WPS PIN is eight digits and exists only for push-button pairing. The serial number is an identifier that support will ask for. On Hikvision recorders, the six capital letters printed as the verification code are a stream encryption key for Hik-Connect, not the login for the web interface — that catches installers constantly.

Labels in awkward places

Cameras and access points frequently hide the label under the mount or behind the bracket, so the credential is only readable while the unit is down from the ceiling. On Dell PowerEdge servers it is on the slide-out tag at the front. A regime 2 device whose label you cannot reach is one reset away from an RMA conversation.

Advertisement

The admin password is not the Wi-Fi password

The Wi-Fi passphrase authenticates a radio association. It gets a device onto the network and no further. The admin password authenticates a session against the management web server running on the router’s LAN address, which is a different piece of software with a different credential store. Changing one does not touch the other. Knowing one tells you nothing about the other.

Virgin Media hubs make the distinction unusually explicit: the base sticker carries a Settings password and a Wi-Fi password, printed inches apart, clearly labelled, and different strings. Most other vendors are less helpful about it.

If you can load a web page, you already have the Wi-Fi key — your device is associated. That fact is completely uninformative about whether you can get into 192.168.1.1. Conversely, plugging into a LAN port with an Ethernet cable gets you to the management interface without any Wi-Fi credential whatsoever, which is why that is the right way to approach a router whose wireless settings you have just broken.

Why vendors moved away from universal defaults

Mirai is the hinge. The source code released on 30 September 2016 carried a hardcoded list of sixty-odd credential pairs harvested from real product defaults: root/xc3511 from XiongMai camera boards, root/vizxv, root/54321, support/support. The malware scanned Telnet, tried the list, and built a botnet large enough to take down Dyn’s DNS infrastructure on 21 October 2016, and a large slice of the consumer internet with it. Nothing about the attack was clever. It worked because regime 1 makes a single credential pair worth millions of devices.

Regulation followed, and it followed with unusual specificity. California’s SB-327 took effect on 1 January 2020 and requires a connected device to either ship with a password unique to each unit, or force the user to generate new authentication before first access — regimes 2 and 3, written into statute, with regime 1 written out. Oregon enacted a close equivalent. ETSI published EN 303 645 in June 2020, whose provision 5.1-1 requires device passwords to be unique per device or defined by the user; the standard was revised twice in 2024.

The UK went further. The Product Security and Telecommunications Infrastructure regime took effect on 29 April 2024, banning passwords based on incremental counters, passwords derived from publicly available information, and passwords derived from a serial number or other unique identifier unless protected by encryption or a keyed hash. The EU’s Cyber Resilience Act, Regulation 2024/2847, requires products to reach the market with a secure-by-default configuration; its vulnerability reporting obligations bit on 11 September 2026, and the main product requirements arrive on 11 December 2027. We cover the compliance detail separately in what PSTI and the CRA actually require of default passwords.

None of this is retroactive. A DVR manufactured in 2013 is still a regime 1 device sitting on somebody’s network, which is why a corpus of confirmed fixed defaults remains operationally useful rather than merely historical — see what the current dataset actually shows for how the distribution looks across manufacturers and device classes.

What each regime means when you reset

Pressing the pinhole means something different in each case, and getting this wrong is how people lock themselves out of hardware permanently.

  1. Fixed universal: you get the documented pair back. The reset is recoverable by definition. Look the model up, log in, and change the password before you do anything else — you have just restored a credential that is public knowledge.
  2. Per-unit: you get the original label value back, not a new one. This is the most damaging misconception in the whole subject. A factory reset does not generate a fresh random password. It restores the one printed on the sticker at manufacture. If the label has worn off, been painted over, or the unit is mounted where you cannot read it, the reset has not helped you and may have cost you your working configuration.
  3. Set at first use: you land back in the wizard. You cannot be locked out, which is the good news. The bad news is that between the reset completing and you finishing setup, the device is claimable by anyone who can reach it — on a shared or public network that window matters.
  4. None: you get an open management interface. Reset restores unauthenticated access. Do not do this to a device with a routable address and then go to lunch.

Resets on ISP-supplied kit

Hubs managed over TR-069 phone home to the provider’s auto-configuration server shortly after they come back up, and can be pushed a configuration that includes management credentials. The label value can work for a couple of minutes and then stop. That is one of several reasons a reset appears not to have taken — we go through the rest in why the default password does not work after a factory reset.

A partial fifth case is worth recognising: devices where authentication has moved off the box entirely. A UniFi access point adopted by a controller, or anything managed from a vendor cloud account, has no meaningful local default because the credential lives in your account rather than the hardware. Resetting it does not produce a password; it produces an unadopted device waiting to be claimed again.

Do this before the reset, not after

Photograph the label of every regime 2 device as you install it, serial included, and put the image somewhere you will find it in three years. A per-unit password is the only kind that can be lost permanently, and those few seconds are the entire mitigation. If you are holding an unmounted camera or a router that is about to go behind a cabinet, now is the moment.

Advertisement
Facebook
Twitter
LinkedIn
Email
WhatsApp

MORE FROM ROUTERPASSWORDS.COM