What is a universal default password?
A universal default password is a single login credential — like admin/admin or admin/password — that's identical across every unit of a given device model, documented publicly in the manufacturer's manual or support pages.
This is the pattern that made "router default passwords" a real security problem: because the same credential works on every unit of that model, anyone with access to the manufacturer's documentation (or a widely-shared list) can log into any un-changed unit of that model, anywhere. It's the exact opposite of the safer patterns — a unique password per device, or forcing the owner to set one at first setup.
This is also the pattern now restricted by law in several jurisdictions: the UK's Product Security and Telecommunications Infrastructure (PSTI) Act and the EU's Radio Equipment Directive / Cyber Resilience Act both prohibit universal default passwords on new consumer connectable products, specifically because of this shared-credential risk.
ssid.ai's Compliance Index tracks exactly this — what share of a manufacturer-cited directory of router models still ships a universal default, versus the safer alternatives (unique per-device password on the label, forced setup, or app-only management with no direct web login).
FAQ
- How do I know if my router has a universal default password?
- Check its model on the ssid.ai router directory — every model is tagged with its actual credential type (universal default, unique label password, set-on-setup, or app-only), cited to the manufacturer's own documentation.
- What should I do if my router has a universal default?
- Change it immediately from the router's admin panel (reachable at its default gateway address) to a strong, unique password. A universal default is safe only until someone else who knows it can reach your router's admin interface.
- Are universal default passwords illegal now?
- For new consumer connectable products sold in the UK (since the PSTI Act took effect in April 2024) and, on a rolling basis, the EU (under the Cyber Resilience Act / RED), yes — manufacturers can no longer ship a universal default password on new products. Older, already-sold devices aren't retroactively affected.