Disable or Secure Captive Portal
Disable the captive portal or protect it with a password before putting your Konnected device into regular use.
The captive portal makes it easy to connect a new Konnected device to WiFi. It is enabled by default and provides a fallback setup network whenever the device cannot connect to its configured WiFi access point.
The default setup network has a unique name in the format konnected-xxxxxx, but it does not require a password. We recommend disabling the captive portal or protecting it with a password after you finish setting up the device.
This article applies to Konnected devices running ESPHome firmware with WiFi enabled. If you need to connect a device for the first time, see Connecting to WiFi using a Web Browser (Captive Portal).
Why the default setting needs attention
When a Konnected device is connected to your WiFi access point, its captive portal setup network is not active. If the device loses that connection, it starts its own WiFi access point so you can provide new credentials.
With the default open configuration, anyone within WiFi range can join that setup network and change the device's WiFi credentials. An attacker who can disrupt the access point or WiFi network used by the device could cause the setup network to return, then use it to take control of the device.
Changing the setup network name or WiFi channel does not protect access to the captive portal. Disable it or set a password.
Option 1: Disable the captive portal
Disabling the captive portal is the most secure option when the correct WiFi credentials are embedded in the device firmware. In the Konnected Mobile App, go to Settings > Network > WiFi Credentials and set the WiFi network name (SSID) and password for the device. These values are included in the customized firmware built for the device. If the device loses its WiFi connection, it will not broadcast a setup network.
Use this option when:
- The correct WiFi network name and password are set under Settings > Network > WiFi Credentials in the app.
- The device connects reliably to that network.
- You have physical access to the device if you need to recover it.
If the embedded WiFi credentials are wrong, change, or no longer lead to an available network, you will need to manually reflash the firmware to reconnect the device. Confirm the embedded credentials before disabling the captive portal.
Option 2: Protect the captive portal with a password
Set a captive portal password if you want to keep the fallback WiFi setup method available. The device can still broadcast its setup network when it cannot connect, but a nearby person needs the password before joining it.
Use a strong, unique password that is different from the password for your primary WiFi network.
You can also change the setup network name from konnected-xxxxxx and select the WiFi channel used by the setup network. These settings can help you identify the device or place its setup network on a different channel, but neither setting replaces password protection.
Change the settings in the Konnected Mobile App
- Open the Konnected Mobile App and select your device.
- Go to Settings > Network > Captive portal.
- Disable the captive portal, or leave it enabled and enter a password.
- If needed, change the setup network name or WiFi channel.
- Tap Save & Continue, then Build Now.
- When the build is ready, tap Update Now to install the updated firmware on the device.
The setting does not take effect until the updated firmware is installed. See Updating Firmware with the Konnected App for more about the build and update process.