I have a couple of PW2s installed, connected via ethernet only (isolated on its own VLAN, though Tesla is total garbage about basics like "what firewall rules are needed"), no cellular here either. But the TEG-$(SERIAL){3} network has always been right there anyway, which is just really lazy design. I happen to be physically far enough away from anyone else that it's very unlikely to be a security issue in practice, but it's still unnecessarily polluting WiFi even beyond that. This has been noticeable for a long time too, it's not hard to find threads going back a long ways with people asking how to disable the gateway WiFi, ie., (
https://teslamotorsclub.com/tmc/threads/disable-gateway-wifi... ), or people speculating about the obvious vuln/interference implications. From that thread back in June:
>It would be nice to find a way to turn off the TBG's WiFi hotspot. I already have too many WiFi hotspots in my area for my taste. TBG's broadcasting WiFi is just a exploit waiting to happen.
The whole thing is genuinely perplexing. Dependence on WiFi, while regrettable, I guess can sometimes make sense from a "user friendly" perspective for a lot of typical consumer installed gear. But the PowerWalls are absolutely not consumer installable, nor obviously in any way inherently wireless. They represent serious electrical infrastructure, and require professional installation with a lot of run cable. Adding in some shielded cat 5 or whatever along with that is frankly trivial for multi-thousand/ten-thousand dollar professional projects, even when not dealing with people who can do a drop themselves.
Minimizing attack area is really trivial security, and here it's got other bonuses like just being more reliable. The entire IOT space is full of shit of course, but it seems much stranger in this instance to me than something like lightbulbs. And why even have passwords at all for access versus using keys? None of this is supposed to be generally accessible anyway. It's not like this would cost Tesla anything extra.
Edit to add: HOSTNAME INCLUDES THE FULL SERIAL. I thought I'd take a second look at this and just pulled up the client info for the PW2 Gateway on my network, and hostname is 11XXXXX-00-J--S$(SERIAL). So no local physical access is required, the gateway itself just broadcasts the whole serial, which in light of this is an, interesting, decision. I can confirm that using the hostname with an added S at the front (so on mine serial was T[...], I used the password ST[...]) I was able to connect to the WiFi spot, and in turn to the management page described. Incredible.
Incidentally DPI is also kind of wacky now that I look, just running a simple Suricata setup but connections are all over the place (why is YouTube showing up?). About 4.5 GB down and 9 GB up, down I assume would be updates of some kind, up monitoring data though that seems like a significant amount for what should generally be text. I haven't had it that long, must be kind of chatty.