ssid.aiAPI

What is a universal default password?

A universal default password is a single login credential — like admin/admin or admin/password — that's identical across every unit of a given device model, documented publicly in the manufacturer's manual or support pages.

This is the pattern that made "router default passwords" a real security problem: because the same credential works on every unit of that model, anyone with access to the manufacturer's documentation (or a widely-shared list) can log into any un-changed unit of that model, anywhere. It's the exact opposite of the safer patterns — a unique password per device, or forcing the owner to set one at first setup.

This is also the pattern now restricted by law in several jurisdictions: the UK's Product Security and Telecommunications Infrastructure (PSTI) Act and the EU's Radio Equipment Directive / Cyber Resilience Act both prohibit universal default passwords on new consumer connectable products, specifically because of this shared-credential risk.

ssid.ai's Compliance Index tracks exactly this — what share of a manufacturer-cited directory of router models still ships a universal default, versus the safer alternatives (unique per-device password on the label, forced setup, or app-only management with no direct web login).

FAQ

How do I know if my router has a universal default password?
Check its model on the ssid.ai router directory — every model is tagged with its actual credential type (universal default, unique label password, set-on-setup, or app-only), cited to the manufacturer's own documentation.
What should I do if my router has a universal default?
Change it immediately from the router's admin panel (reachable at its default gateway address) to a strong, unique password. A universal default is safe only until someone else who knows it can reach your router's admin interface.
Are universal default passwords illegal now?
For new consumer connectable products sold in the UK (since the PSTI Act took effect in April 2024) and, on a rolling basis, the EU (under the Cyber Resilience Act / RED), yes — manufacturers can no longer ship a universal default password on new products. Older, already-sold devices aren't retroactively affected.

Related