What does router WPS mean? I used one-touch connection for three years, understood the PIN code principle, and turned it off the same day

the button on the router with an arrow or a small lock icon is WPS. My first TP-LINK was used for three years. When I visited, I pressed this button to connect to the internet, and it felt super premium. Until a friend of mine used a laptop and an external network card in the parking lot downstairs from my house to get a neighbor's network PIN running WPS, the first thing I did after getting home was to go to the backend and turn off this feature.
WPS simply means not entering a password, even if you don't enter a WiFi
WPS is called Wi-Fi Protected Setup, developed by the Wi-Fi Alliance in 2007. The starting point was simple: back then, WiFi passwords often mixed a few digits of WPA2, and elderly and children at home would enter it once and make three mistakes. So manufacturers came up with a "password-free" solution.
two common gameplay methods. One is the Button (PBC) : Press the WPS key on the router, and within two minutes, you select this network from your phone's WiFi list, which automatically pairs and connects without touching the keyboard. The other is PIN code : the router's sticker or backend displays an 8-digit number, which the new device can enter to connect to the network. Some older laptops even have a "virtual WPS button" in their network card management software, which works just like a physical key.
sounds pretty considerate, right? The problem lies in the PIN code process—the button-based system itself is relatively clean, but most routers have both WPS enabled and PIN verification enabled. If you don't use it, the backdoor is open too.
Why can
8 PIN run in just a few hours
math account of this is especially frustrating. The PIN is an 8-digit number, and the 8th digit is a check bit calculated from the first 7 digits, meaning only 7 digits are actually being guessed. What's worse is that when the router authenticates it splits into two : first tell you whether the first 4 bits are correct, then verify the last 3 bits. The top four can be tested up to 10,000 times, the last three up to 1,000 attempts, totaling a maximum of 11,000 attempts, and PIN is guaranteed.
At the end of
2011, CERT in the US issued a notice advising all users to disable WPS; When the open-source tool Reaver was released in early 2012, anyone could repeat this phenomenon. An external network card is within the signal range, and a regular home router can run for 4 to 11 hours to exit the PIN. After the PIN appears, according to protocol, the router must send the WPA2 password to the device that has been verified—in other words no matter how long or twisted your password is, the WPS port is open, and the router hands over the key itself. When I wrote about WPA2 and WPA3 before, I said, 'Ninety percent of the cracked passwords aren't because of encryption, but because WPS wasn't turned off. I'll explain this later.' That's the one I wrote about later.
some people may ask: If my router keeps entering the wrong PIN and it locks, does that mean it's safe? Locking does exist—as short as 60 seconds, as long as 24 hours—but there are two ways to bypass it: one is for the attacker to slow down and test slowly; the other is to unplug and restart. Most firmware restarts and locks are gone, but the progress is still there. By the way, those who want to ride the internet first need to reach your home's signal, the signal range issue mentioned in that anti-internet is also a prerequisite.
add some background. The problem of half-and-out verification was discovered in 2011 by Austrian researcher Viehböck, who figured out that an ordinary computer could finish it in just a few hours. Over the next decade or so, manufacturers kept patching patches, but patches basically did one thing: extending locking time, limiting retrys, and splitting the old logic of splitting in half for verification never changed. So don't be fooled by the fact that routers were newly purchased in recent years. Some new firmware WPS implementations are essentially the same as those from over a decade ago—turn them off if you can, and that's it.
After I turned it off, only one device in the family had a falling out
Before
shutdown, I also had doubts: with seven or eight devices at home, would they all disconnect? The actual result was cleaner than I thought—when reconnecting phones, computers, or TV boxes, you just enter the password normally. These devices don't use WPS at all; the pairing history only shows the password.
The only thing
turned against was an old 2014 HP printer, which only had a WPS button option in the wireless network menu, without a password entry entry. After pulling out the manual, I found the solution: select 'Manual Input' in the wireless settings on the printer's panel, then use its small screen to type the password letter by letter, and it takes two minutes to solve the problem. My mother-in-law's old TV was even more extreme. After choosing WiFi, it didn't have a virtual keyboard and had to rely on WPS pairing. This was a true exception—either keep WPS or grit your teeth and buy a TV box costing just a few dozen yuan to replace its wireless functionality.
the actual cost of turning down WPS is much lower than you might think. Before you worry about "what if a device can't connect," think first: when these devices first connect to the internet, did you enter a password or press a key? Ninety percent of people have never pressed a single button.
Before
the end, take a look: three pitfalls that can't be fully completed
first, how to check if your device is enabled. There are simple tricks without going into the backend: check the bottom sticker of the router and see a string of 8-digit PIN codes, which basically support WPS and are enabled by default; Then open the WiFi details page with your phone; if it has an entry like "Connect via WPS," it's open. Machines manufactured before 2012 can almost be left running by default.
the first pitfall: PIN the button was turned off but the was on. Some backend apps are split into two switches: "disable PIN code" and "disable WPS," each managing one separately, effectively closing one for nothing. The second pitfall is virtual buttons in mobile apps. Some brands' apps use the WPS channel for "one-click network access," but the background is off, but the switch in the app is still active. The third pitfall is that turn off and then rebound on its own. A few carrier-customized machines automatically revive WPS after rebooting, just like ITMS late-night spec pushes—if you encounter it, you just check it every other day.
check if it's turned off completely. Here's a trick: take your phone and click on your home network in the WiFi list. If the details page still has options like "Connect via WPS," either it disappears or you click it but nothing happens—only then is it considered correct. New devices use passwords as usual, and like vacuum cleaners and cameras that only recognize 2.4G, you'll never need WPS—don't leave them a backdoor.
Compare the closing paths in each brand's backend
I recorded all the backends I took, the new and old interfaces have different names. If they don't match, use the backend search box to search for "WPS" or the old name "QSS":
| brand | turn off the path | notes |
| TP-LINK / Mercury | wireless settings → WPS one-touch setup → Disable | old firmware called "QSS Security Settings" |
| Tenda | Wireless Settings → WPS → Disable | old AC series mixed in the wireless encryption page |
| ASUS | Wireless Network → WPS tab → Enable WPS and turn it off | After closing it, also confirm "Enable PIN" |
| Xiaomi / Redmi | 192.168.31.1 → In Wi-Fi settings, find WPS | some new firmware has been removed; Mijia App One-Click Access Account Binding, Not WPS PIN, No Need to Panic |
| Carrier Optical Modem | 192.168.1.1 / 2.1 → WLAN Settings to find WPS | customized device menus are diverse. If you can't find it, call customer service to close the |
Who can be kept? My order of handling
isn't a one-size-fits-all approach. Keeping these three types of homes without signal going through the yard wall, having only that old TV without a keyboard relying on WPS and no one to help migrate it—these three types are not a big problem, since the premise of an attack is that the other side can reach your signal. If you live in an elevator apartment, have close building distances, or rent properties that change hands frequently, it's only a matter of two minutes—don't hesitate.
add another word about rental and second-hand housing scenarios. The network you took over might have had the router installed by your previous owner, and you have no idea what the status of WPS is. The first thing to do is check two things in the backend: have you changed your WiFi password? Have you turned off WPS? I helped two friends check the routers they took over. One had WPS running, and the background password was still in the admin default state, meaning both doors were left open. For this kind of machine, don't just disable WPS; change the backend management password at the same time. If that doesn't work, just reset and reconfigure the setup. Anyway, the whole redialing process can be done in half an hour.
my order to copy for you: go to the background and turn off WPS (check both switches) → Phone verification The 'Connect via WPS' option is invalid; → If you have an old printer or TV, manually enter the password to transfer it once → Conveniently change the WiFi password to a 16-bit hybrid one. The process for changing password is in this article. This switch and UPnP switch like a pair of brothers in trouble—both are on by default, and none should be on by default. When you go to the backend to those security settings you can do them all at once. Remember this sentence: the password is a lock, WPS is your own window—if you don't use it, you should close it.
