What Is UPnP? Should You Turn It Off on Your Router?
A convenience feature that lets any program on your network punch holes in your firewall. Here is what to do about it.
Published October 2026 · Sources: 7 · ismyroutersafe.com
UPnP (Universal Plug and Play) lets devices on your network find each other and open ports in your router automatically. CISA, the NSA and the FTC all say to turn it off unless you need it. The protocol has no authentication, and malware has used it to get around router firewalls.
What does UPnP do?
CISA calls UPnP a handy feature that lets networked devices discover and talk to each other. On a router, it can also let a device add port mappings, so traffic from the internet can reach it.
CERT/CC notes UPnP was designed for trusted local networks and has no form of authentication. The router does not check who is asking.
From the team behind this checker
Want a router that takes this seriously by default?
SecureRooms. Smart devices live apart from your computers.
$199.99 · 1 year of VPN included, then $7.99/mo · 30-day returns · 1-year warranty. Rio builds this site and grades its own router by the same method.
Why is UPnP a security risk?
Malware can open holes. CISA says malware inside your network can use UPnP to bypass your router’s firewall, let attackers control devices remotely and spread to other devices.
Some routers expose it to the internet. CERT/CC calls that a misconfiguration, but said in 2020 that scans still found such devices online.
Buggy code. In 2013, CERT/CC warned that a common UPnP library had flaws that could let a remote attacker run code. Rapid7 estimated about 20 million devices using it were exposed directly to the internet.
Traffic floods. In 2020, CERT/CC described CallStranger (CVE-2020-12695), a UPnP flaw that could be abused for DDoS attacks and data exfiltration.
Hijacked routers. Akamai found 45,113 routers with injected UPnP rules that exposed 1.7 million computers behind them to attackers.
What do government agencies advise?
CISA: disable UPnP unless you have a specific need for it.
NSA: disable UPnP, along with remote administration, to help close holes attackers use.
FTC: turn off UPnP, remote management and WPS, which are convenient but can weaken security.
FBI and NSA (2024): threat actors may abuse UPnP on routers and smart devices to get in or spread malware, so disable it if not needed.
What changes if you turn it off?
Devices can no longer open ports in your router by themselves. Anything that relied on that for incoming connections may not work as before.
If that happens, check the device maker’s support pages for the exact ports it needs, and forward only those. That gives you one known, fixed opening instead of letting any program create its own.
How do you turn off UPnP?
Log in to your router from a device on your home network.
Find the UPnP setting. Look under advanced, NAT or network settings. Names vary by brand.
Turn it off and save.
Test the devices you care about, such as game consoles and cameras.
Update the firmware. CERT/CC’s fix for the 2013 UPnP flaws was updated software, so stay current.
Government guidance says no, unless you need it. CISA, the NSA and the FTC all recommend turning it off, because malware inside your network can use UPnP to bypass the router firewall.
No. UPnP does not control your speed. It only lets devices discover each other and ask the router to open ports.
Not necessarily. If a game or console has connection problems with UPnP off, check its maker’s support pages for the ports it needs and forward only those.
On some routers, yes. CERT/CC says exposing UPnP to the internet is a misconfiguration, yet scans in 2020 still found devices doing it. A 2013 flaw in a common UPnP library could let remote attackers run code.
Port forwarding is a rule you set by hand for one device and port. UPnP lets devices create those rules themselves, with no password, which is why agencies advise turning it off.
Sources
Dates show when each source was published or when we checked it.