Knowledge Base
AVM Content
- FRITZ!Box 7690
- FRITZ!Box 7682
- FRITZ!Box 7590 AX
- FRITZ!Box 7590
- FRITZ!Box 7583 VDSL
- FRITZ!Box 7583
- FRITZ!Box 7582
- FRITZ!Box 7581
- FRITZ!Box 7560
- FRITZ!Box 7530 AX
- FRITZ!Box 7530
- FRITZ!Box 7520
- FRITZ!Box 7510
- FRITZ!Box 7490
- FRITZ!Box 7430
- FRITZ!Box 6850 5G
- FRITZ!Box 6850 LTE
- FRITZ!Box 6820 LTE
Protecting the FRITZ!Box
In addition to computers, smartphones and smart home devices, routers are also increasingly being targeted by hackers. For this reason, every FRITZ!Box is already protected by a unique password and a unique network key in the factory settings. Thanks to the integrated firewall, all devices connected to the FRITZ!Box are fully protected against attacks from the internet.
To offer your FRITZ!Box the best protection against attacks, observe the following security tips and adjust the settings of your FRITZ!Box, if necessary.
Note:All instructions on configuration and settings given in this guide refer to the latest FRITZ!OS for the FRITZ!Box.
1 Installing the latest FRITZ!OS
Regular updates of FRITZ!OS are an important part of our security concept. Since the attack methods used by hackers are constantly evolving, using the latest FRITZ!OS is indispensable for maximum security to reliably protect against new threats:
- Install the latest FRITZ!OS on the FRITZ!Box.
2 Changing the FRITZ!Box password
To prevent unauthorized persons from logging in to the FRITZ!Box with the password on the underside of the device and changing its settings, configure a new password:
3 Setting up secure telephony
To make sure that you are not charged for unauthorized calls to international numbers or premium-rate services, set up call blocks for calls to international numbers and premium-rate numbers:
- Set up call blocks for calls to international numbers and premium-rate numbers in the FRITZ!Box. Instead, you can also have your telephony provider block these number ranges.
4 Securing your Wi-Fi
If the FRITZ!Box is located somewhere where unauthorized persons can access it, configure a new network key and disable WPS (Wi-Fi Protected Setup) in the FRITZ!Box. This way, unauthorized persons cannot use the network key from the underside of the FRITZ!Box or push a button to use Wi-Fi to connect to the FRITZ!Box.
Change the network key
- Click "Wi-Fi" ("Wireless") in the FRITZ!Box user interface.
- Click "Security" in the "Wi-Fi" ("Wireless") menu.
- Click on the "Encryption" tab.
- Enable the option "WPA encryption".
- Select "WPA2 + WPA3" or "WPA2 (CCMP)" for the "WPA mode".
- Enter a new password in the "Network key" field. Use numerals, letters, and other characters, and mix upper and lower case letters.
- Click "Apply" to save the settings.
Disabling WPS
- Click "Wi-Fi" ("Wireless") in the FRITZ!Box user interface.
- Click "Security" in the "Wi-Fi" ("Wireless") menu.
- Click on the "WPS Quick Connection" tab.
- Disable the option "WPS enabled".
- Click "Apply" to save the settings.
5 Setting up secure internet access
If you configured sharings in the FRITZ!Box so that the FRITZ!Box or devices in the home network can be accessed over the internet, we recommend checking the following settings:
Disabling services that are no longer needed
- Click "Diagnostics" in the FRITZ!Box user interface.
- Click "Security" in the "Diagnostics" menu.
- In the "FRITZ!Box Services" section, check which services are set up for access from the internet in the FRITZ!Box.
- Disable the services that you no longer need.
Note:MyFRITZ!Net requires the service "Internet access to the FRITZ!Box (HTTPS)".
Using individual account information
- Click "System" in the FRITZ!Box user interface.
- Click "FRITZ!Box Users" in the "System" menu.
- Give all users unique usernames. Do not use usernames that are easy to guess, such as admin, guest, fritzbox, remote, or user.
- Give all users unique passwords that are strong enough. Do not use any passwords that are easy to guess or ones that you already use for other services, such as an email account, Amazon, Facebook, or Google.
Note:You can find information on strong passwords in our guide Everything you need to know about strong passwords, for example. A password manager like Bitwarden or KeePass can help you keep track of things while also generating cryptographically complex passwords.
Using an alternative HTTPS port
- Click "Internet" in the FRITZ!Box user interface.
- Click "Permit Access" in the "Internet" menu.
- Click on the "FRITZ!Box Services" tab.
- In the field "TCP port for HTTPS", enter an unused port from the range 1024 to 65535 instead of the default port 443. This makes it more difficult for unauthorized persons to determine whether it is even possible to access the FRITZ!Box via HTTPS.
- Click "Apply" to save the settings.
Using an alternative FTP/FTPS port
- Click "Internet" in the FRITZ!Box user interface.
- Click "Permit Access" in the "Internet" menu.
- Click on the "FRITZ!Box Services" tab.
- If internet access to your storage media via FTP/FTPS is enabled, enter an unused port from the range 1024 to 65535 in the field "TCP Port for FTP/FTPS" instead of the default port 21. This makes it more difficult for unauthorized persons to determine whether it is even possible to access the FRITZ!Box via FTP/FTPS.
- Click "Apply" to save the settings.