Replies: 2 comments
|
What's Changed 📦 Version 11 is a new major release of the Battery-Emulator, with many wireless cybersecurity enhancements and MQTT changes that might require attention when updating. Please familiarize yourself with the release notes before OTA updating to this version. This release brings us several cybersecurity improvements. From now on, when the Wi-Fi access point (AP) is running with the factory-default password (123456789), and no client connects to it, it is automatically disabled after 5 minutes (raising a corresponding event). If a custom AP password has been set, behavior is unchanged and the AP stays enabled indefinitely. Limiting the default-password AP to a short provisioning window mitigates the attack vector while keeping first-time setup and recovery access fully functional. The log window had Wi-Fi/AP passwords printed in cleartext, in the settings UI the Wi-Fi/AP/MQTT/HTTP-auth password fields rendered the stored value into their HTML value attribute making it possible for malicious actors to read them. This has changed so that these fields remain empty, and when submitting the form without any of these filled, they will not be changed If you want the AP to be active, change the default AP password to something more cybersecure |
|
Thank you very much for the insightful explanation. |
Uh oh!
There was an error while loading. Please reload this page.
Why does the Wi-Fi AP stop being visible and become undiscoverable after some time?
After power-cycling the device, it becomes visible again for a short while. What could be causing the AP to disappear?
All reactions