Add support for Xiaomi AX1800 Wifi 6 router

A liiiittle off-topic, but it piqued my interest, as I had looked at the local MQTT implementation on Xiaomi routers recently.

Check the references to json_object_new_object if you want to see what kind of responses they build to send upstream.

For example, this is what it sends on connect. (In function ma_sys_info_generate_register_payload)

However, I'm a little more worried about what they can send back to you. Sweats profusely

I really hope that does not look what I think it looks like.

2 Likes

Hi! Thanks for the reply!
I analysed binaries left on the device and I am worried too that there is a persistent connection to the Xiaomi network. I think this is how the mobile application for the router works - it sends commands to the Xiaomi network and the router receives them back via MQTT protocol. I think it is worth knowing for other users that this firmware is persistent-connected to receive many/different commands (RCE).

(btw. Xiaomi can send commands using api.miwifi.com/rom_config.)

1 Like

I wonder if this can be used to root the router by spoofing the mqtt server IP. Is there any encryption/authentication taking place?

Xiaomi firmware uses mosquitto MQTT client.

I've installed "Mosquito MQTT server" on my linux box and redirected the connection from the router to my server (option BROKER_HOST in /etc/config/messaging on the router).

  • Does it uses any authentication? Yes it does but I skipped it using 'allow_anonymous true' in mosquitto config.

  • Does it uses any encryption? Yes it does - messages from the router are encrypted. I think that messages from the xiaomi network may be encrypted too but I haven't seen any.

  • I haven't made a connection to xiaomi mqtt server (yet, no time).

  • Can it be used to root the router (...)?- I think this may be possible if we upload our own (PEM) certificates. This path should be definitely explored.

2 Likes

Nobody manage to activate guest mode on all mesh nodes with fw 3.0.34??

This post was flagged by the community and is temporarily hidden.

hi, Is https-dns-proxy working? ssh fw 3.0.34?

hi,how do you run adblock with what ssh commands? i am a beginner :slight_smile:

I'm using 3.0.34 global (AX1800 white), but there's some error that reset router can't fix. Could you send me global firmware (any version) for this router?

Could you post original 3.0.34 firmware?