In late 2025, a staggering 81% of broadband users were found to have never changed their router’s default administrative password, opening the door to significant malware risk. This widespread negligence was revealed in Broadband Genie’s fourth major router security survey, where 3,242 users were polled to gauge progress on consumer cybersecurity awareness. Despite regulatory pushes […] The post 81% Router Usres Have Not Changed Default Admin Passwords, Exposing Devices to Hackers appeared first on Cyber Security News.
Don’t most routers these days come with a randomised password on the box? I always change to something else, but it strikes me that this problem may already be solved.
We already know people have poor password security.
Many still have a hidden superuser account that can’t be disabled or changed, particularly if you use an ISP-provided device. Usually the password is something “secret” to the provider, so it’s not as bad as root:root, but still… Plus all the possibilities with TR-069 for example. It’s a scary world.

