Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Warning: the process has finished, but seems like ssh connection to the router is not working as expected. #186

Open
Benjeny opened this issue Jan 28, 2024 · 7 comments

Comments

@Benjeny
Copy link

Benjeny commented Jan 28, 2024

Hello, is there someone who can help me ?
First of all, thank you for your work.
I am trying to use the exploit on a Xiaomi Mi4A (Gigabit Edition) router, chinese version, firmware Version 2.28.62
The goal is to flash openwrt.

I have connected my MAC directly to the Mi router (192.168.31.1),followed the video(https://www.youtube.com/watch?v=SLbkce-M2nE&list=PL_Z5kQQ5KSSXOenNFFUOq2qMdOYEzRngq&index=12) of Youtuber, Hoddys Guides,steped by steped. When the viedo at 12:22, showed that"Warning: the process has finished, but seems like ssh connection to the router is not working as expected....", what happened? how and why?

@freddysolorzano
Copy link

I have the same problem but with an r4a router manufactured in 2023.5 with firmware 2.30.28

@AddaxSoft
Copy link

AddaxSoft commented Apr 5, 2024

same on 2.30.28; this exploit command seems to be working and it does reboot the router, but when running the full exploit chain it fails.

http://192.168.31.1/cgi-bin/luci/;stok={{{STOK}}}/api/misystem/set_config_iotdev?bssid=XXXXXX&user_id=XXXXXX&ssid=-h%0Areboot%0A

  • router model: r4a Chinese (gigabit edition)
  • firmware version 2.30.28

@RadioOperator
Copy link

RadioOperator commented Apr 5, 2024

If fw 2.30.28 is the same hardware (Xiaomi 4A v2) with 2.30.20, maybe this issue would help: #141

@AddaxSoft
Copy link

yes it does help as I already mentioned above the initial RCE exploit works (the router reboots) but when the exploit is chained (binary upload, and trying to execute it later for telnet access) something breaks in between

@RadioOperator
Copy link

try to downgrade to 2.30.20 firmware.

@imakiro
Copy link

imakiro commented Apr 9, 2024

Same issue with
Router Mi Router 4A Giga Version, version 3.0.27
Setting up a proxy didn't help : #185

@licryle
Copy link

licryle commented Sep 3, 2024

I just went through the steps in the mentioned thread but found them too complicated.

So created a much easier shell script for 2.30.28 and documented the commands to send, check out #141 (comment).

I also completed the openWRT installation after and updated the post above, though it totally is a simpler rewrite from https://github.com/MrTaiKe/Action_OpenWrt_Xiaomi_R4AGv2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants