A second-hand router is a tempting offer: a fraction of the price, sometimes free from a relative or an old workplace, and often better specified than anything affordable new.

Most are perfectly usable. But one carries something invisible from the outside, the previous owner's settings, and sometimes more.

What actually comes with it

A router stores its configuration inside itself, and that survives any number of changes of ownership. Most commonly left behind:

  • An administrator password that isn't the factory one, leaving you unable to reach your own settings.
  • DNS settings pointed at a particular server.
  • Port forwarding rules opening doors from outside into your network.
  • Remote management switched on.
  • Device lists and the old network name.

Most are harmless leftovers nobody thought to clear. But the three in the middle, left in place, mean your new network runs with doors someone else opened.

Three checks before accepting one

Ideally done before money changes hands, because all three decide whether the device is worth using at all.

1. Does the reset button work

The most decisive check. A router that can't be reset is one you'll never be able to clean, and the previous owner's settings will stay forever.

How to test it is in the guide to factory resetting a router. If after a reset the default password printed on the casing isn't accepted, the device is locked, and isn't worth using.

2. Is it still supported

Look up the model and hardware revision on the manufacturer's site and check when its last firmware was published. A model unsupported for years isn't merely dated, it's exposed to publicly known holes, and those will never be closed.

The reasoning matches the guide to when a router should be replaced. A second-hand router that's out of support is a router at the end of its life, however pristine.

3. Where it came from

Two origins call for extra care:

  • ISP-supplied. Often locked to their service and not fully resettable by the user. Some remain the provider's property rather than the holder's.
  • Ex-office. Business-class equipment is sometimes still enrolled in that company's central management system, meaning its settings can still be changed remotely by someone who isn't you.

Cleaning it properly

The order matters, for the same reason it does after a compromise, see the guide to recovering after a Wi-Fi breach.

  1. Reset with the physical button, not through a menu. Press and hold as the model requires, usually ten seconds until the lights flash together.
  2. Connect by LAN cable, not Wi-Fi. Until the configuration is sorted, the wireless network still uses the default password printed on the casing, known to anyone who has ever seen it.
  3. Update the firmware before configuring anything. A reset doesn't touch firmware; if the way in was there, it's still there afterwards.
  4. Change the administrator password first, then the Wi-Fi password. This order must not be reversed.
  5. Check the four things most often left behind: DNS settings, port forwarding rules, the list of admin accounts, and remote management.

After that, set it up as if new, with the guide to setting up a new router and the guide to securing a home router.

Signs it shouldn't be used

  • A reset doesn't restore the default password. The device is locked, or its firmware has been replaced with something that isn't original.
  • The settings pages look unfamiliar: an interface matching no image on the manufacturer's site.
  • It powers on but never settles, or runs hot from the start. That may be age rather than security, see the guide to router overheating, but it's still not something to build a network on.
  • No model or serial label. Without those you can't check its firmware, and you can't establish where it came from.

If you're the one giving it away

The reverse direction matters just as much, and is forgotten more often.

  • Factory reset it, then verify the network name really has returned to default. A failed reset looks exactly like a successful one.
  • Remove the SIM card if it's a cellular router, see the guide to MiFi and 4G routers.
  • Peel off any stuck-on notes. A Wi-Fi password written on a sticker and left on the casing is the most common leak of all, and the easiest to prevent.

What you needn't worry about: browsing history. Home routers generally don't keep it, the retention duties covered in the guide to log retention apply to service providers, not to household equipment.

The bottom line

A second-hand router is worth using, on two non-negotiable conditions: it can be reset, and it's still supported. One that fails either isn't a saving, it trades the cost of hardware for a risk you can't see.

If both hold, the cleaning order decides the rest: reset, connect by cable, update firmware, then change the administrator password before the Wi-Fi one.

Frequently asked questions

Are second-hand routers safe to use?

Safe if two conditions hold: it can be factory reset, and it still receives firmware updates from its manufacturer. One that fails either is best not used for your main network, however good its physical condition.

Is a factory reset enough to clean it?

For virtually any ordinary case, yes. A reset restores every setting changeable through the admin pages. What it doesn't replace is the firmware itself, which is precisely why updating firmware is the second step you can't skip.

What about routers from an old office or from an ISP?

ISP-supplied routers are often locked to their service and can't be fully reset by the user. Ex-office equipment is sometimes still registered with that company's central management system. Both need confirming before use at home.

What should I do before giving my old router away?

Factory reset it, then verify the network name and password really have returned to defaults. Remove any SIM card. What's most often left behind is the note with the old Wi-Fi password stuck to the casing.