TechKnowSurge
VideoSecurityFree

Hardening - Change Default Passwords

Default credentials on network hardware pose a serious security risk, as they are publicly documented and can be exploited by anyone with network access. Changing credentials immediately upon device setup is a fundamental step in securing any environment.

Complete this video to capture a CTF flag worth 1 point.

About this video

Network hardware such as routers and switches typically ships with factory-set default credentials, a practical manufacturing decision that creates a significant and well-documented security vulnerability. Because manufacturers apply the same username and password combination across thousands of identical units, these credentials are widely published online and trivially easy to look up. Any attacker who can reach the device over the network can use those credentials to gain full administrative access without any special tools or technical sophistication. Some manufacturers attempt to reduce this risk by printing a unique credential set on a label affixed to each individual device, which eliminates the problem of universal default passwords. However, this approach introduces a different exposure: anyone with physical access to the device can read those credentials directly off the hardware, making physical security a prerequisite for that approach to be effective. Regardless of how a device arrives, changing its administrative credentials immediately upon deployment is a foundational security control. Setting a strong, unique password specific to the environment ensures that publicly available default credential databases offer no advantage to an attacker, and it limits the blast radius if one device in a network is ever physically inspected or accessed by an unauthorized party.

What you'll learn

What's covered

Default Credentials Risk

Key terms

Default Credentials
Factory-set usernames and passwords that ship with network devices, applications, and services. Default credentials must be changed immediately upon deployment because they are publicly documented and frequently targeted by automated attackers.
Authentication
The process of verifying the identity of a user, device, or system.
Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Attack Surface
The total set of points in a system where an unauthorized user can attempt to enter or extract data.
Brute Force Attack
An attack method that systematically tries all possible combinations of passwords or keys until the correct one is found.

Topics

Network Hardening Default Credentials Password Security Network Hardware Cybersecurity Fundamentals Authentication

Transcript

Default Credentials on Shipped Hardware

A lot of hardware, when you purchase it, comes with some sort of default credentials. One of the things we're going to want to do is change those default credentials.

Here is a home router. This home router comes with default credentials on it, because it's too hard for them to track and individually change the settings on each one of these devices so it has a different set of credentials on it. So what they do is they just mass-produce these things and send them out.

The problem is that you access management of this via the network. So all I need to do is be on the network. I can use those default credentials to get onto this device, and now I can start installing malicious software on here, or I can do something to compromise this network. So that is problematic.

Now, I have seen a couple of cases where on the back they'll have a little sticker that gives you the admin credentials to log on to the box and then change things on the box. That's better, because it's not all the same — I can't just go online and look up what the default credentials are. But it's still problematic, because anybody who has physical access to the box can see what those credentials are.

So what you're going to want to do, no matter what, as one of the first things when you get these devices, is change those credentials on there so it is unique to your setup and to your environment.

How Easy It Is to Look Them Up

If I didn't change the default credentials, all I need to do is look up TP-Link — and this is a TL-WR940N — default credentials, if I spell that right, and then hit enter. One of the first things that comes up is admin: they are admin for both the username and password. So to get into this device, I would just use admin, admin — admin for the username, admin for the password — and then I'd be in this device. It's as simple as that. I've now hacked into this device.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →