hello,
I have an (internal) wifikit in my Omnik 3.0 inverter, but there is a security problem with it. Hacking the access point and then my own home network is very easy:
1. hackers can log in on the unencrypted access point and then login with the default passwords (admin/admin)
2. hackers can then click on "show key" to see the WPA2 encryption password of my
own WPA2 protected home network.
3. after that hackers can gain access to my own homenetwork with my PC's, NAS's and other devices.
4. This is very unsecure
Changing the default passwords of the internal webserver is not sufficient, as the access point is unencrypted and the passwords can be "sniffed" very easily (due to the case that there is no encryption).
I have tried this with the access point of my own inverter and I could hack it within 30 seconds and hack my own wifi home network within 60 seconds.
The wifi access point ("AP_6023xxx") is unencrypted and the current firmware does not support encryption. I have tried to add encryption, as decribed in this document:
http://www.omnik-solar.com/faq/attachment.php?aid=15
However "http://10.10.100.254/m2m/ap_config.asp" does not exist. It says "404 file not found". So i can
not add encryption to the open access point of the inverter.
I have internal wifi card with version 6023xxxxxx and firmware version is 4.01.9d1.
Is it supported to add WPA2 encryption to the internal wifikit? Or do I have to exchange the internal wifikit for an external kit with ethernet connector (and disable wifi)?
Hope that someone has an answer to this.