Overview I recently replaced my Xiaomi router with a Huawei one. I had heard about the benefits of flsahing a soft router such as ad blocking and unlocking restricted music services. This gave me the perfect opportunity to put the Xiaomi 4A to good use before it collected dust.
Prerequisites
Important: The router must be operating in router mode. Access point (bridge) mode will not allow you to enable telnet access.
Updating System Components If you are already on the required version, you may skip this step.
Upgrading WSL to WSL2 First, enable the following two Windows features in your system to install WSL:
Enable "Windows Subsystem for Linux" Enable "Virtual Machine Platform"
Download the Microsoft WSL2 update package and install it. Use PowerShell to set the default WSL environment to WSL2:
wsl --set-default-version 2
For detailed instructions, refer to the official Windows Subsystem for Linux Installation Guide for Windows 10.
Installing Kali Linux WSL This guide requires a Python environment for operations. Using Ubuntu WSL on Windows 10 provides a convenient and fast way to proceed. Follow similar steps as installing Ubuntu WSL from the Microsoft Store to install Kali Linux WSL. After installation, you can modify the software sources by accessing the sources list through File Explorer and editing it with Notepad.
Kali Linux mirror sources for China:
# University of Science and Technology of China
deb http://mirrors.ustc.edu.cn/kali kali-rolling main non-free contrib
deb-src http://mirrors.ustc.edu.cn/kali kali-rolling main non-free contrib
# Alibaba Cloud
deb http://mirrors.aliyun.com/kali kali-rolling main non-free contrib
deb-src http://mirrors.aliyun.com/kali kali-rolling main non-free contrib
# Tsinghua University
deb http://mirrors.tuna.tsinghua.edu.cn/kali kali-rolling main contrib non-free
deb-src https://mirrors.tuna.tsinghua.edu.cn/kali kali-rolling main contrib non-free
Alternative: You can use Anaconda for this process. However, note that when using OpenWRTInvasion on Windows, the pycrypto package may be outdated and difficult to install, potentially requiring C++ build tools and causing additional errors. Using a Linux environment directly is recommended for a smoother experience.
Using Ubuntu WSL You can set up a graphical desktop using xfce4 combined with xrdp for remote access from Windows 10. This allows you to interact with Ubuntu WSL through a familiar desktop interface.
Installing Required Dependencies
Install Python:
sudo apt-get install python3.6
sudo apt-get install python3-pip
Install Git:
apt-get install install git
Enabling Graphical Interface in Kali WSL Kali Linux provides Win-KeX, a convenient tool for operating WSL systems with a graphical interface. Install it with:
sudo apt install -y kali-win-kex
Basic Win-KeX Commands:
# Launch kex
kex
# Stop or exit kex
kex kill
kex stop
Troubleshooting kex Startup Issues If you cannot start kex, try the following:
# Allow VNC to accept connections from non-localhost (WSL2 and Win10 use different network segments)
vncserver -localhost no
# Terminate kex sessions
kex kill
kex stop
Alternatively, restart your physical machine. In most cases, the connection should work after restarting.
Exploiting Router Vulenrability to Enable Telnet Obtaining the STOK Navigate to the router management page at http://192.168.31.1/, log in, and copy the URL. The address typically looks like:
http://192.168.31.1/cgi-bin/luci/;stok=xxxxxxxxxxxxxx/web/home#router
The value following stok= is the STOK you need.
Note: Access the router management interface through the Kali Linux browser to obtain the STOK. Then use this STOK with OpenWRTInvasion in Kali. Different clients may generate different STOK values. If you obtain the STOK from your Windows browser and then use it in Kali with OpenWRTInvasion, you may encounter connection failures with the error: telnet: Unable to connect to remote host: Connection refused.
Using OpenWRTInvasion Use the OpenWRTInvasion tool to enable telnet access. First, clone the repository:
git clone https://github.com/shenmeiqian/OpenWRTInvasion.git
Then execute the script:
pip3 install -r requirements.txt
python3 remote_command_execution_vulnerability.py
When prompted:
Press Enter to use the default IP: 192.168.31.1 Paste the STOK obtained in the previous step The script will automatically enable telnet access
Upon completion, you should see a success message indicating you can now connect to the router with credentials: (user: root, password: root)
Accessing Router via Telnet and Flashing Breed Downloading Remote Access Tools You will need PuTTY and WinSCP portable versions. These tools allow you to connect to and transfer files with your router.
Connecting to the Router Connect from Kali Linux using:
telnet 192.168.31.1
If telnet is not installed in Kali, install it first. Alternatively, you can use PuTTY from Windows. The login credentials are username: root with an empty password.
Backing Up EEPROM The EEPROM contains crucial router configuration data including calibration information. Failing to restore this after flashing can result in poor wireless signal strength or instability.
dd if=/dev/mtd3 of=/tmp/eeprom_backup.bin
Use WinSCP to transfer the backup file to your computer:
Log into WinSCP Right-click on the file and select download
Flashing Breed
Download Breed for your router model:
cd /tmp && wget --no-check-certificate https://breed.hackpascal.net/breed-mt7688-reset38.bin && mv breed-mt7688-reset38.bin breed.bin
This breed version is compatible with Xiaomi 3A, 3C, 4A (100M), and 4C. Alternatively, download the file to your computer first, then upload it to the router using WinSCP.
Flash the bootloader:
mtd write breed.bin Bootloader
Flashing OpenWrt Firmware Firmware Download Download the appropriate OpenWrt firmware for your router model from a trusted source.
Entering Breed Mode To enter Breed mode, use an Ethernet cable to connect your computer directly to the router. After flashing Breed, press and hold the router's reset button, then power on the device. Access Breed at http://192.168.1.1 from your browser. To re-enter Breed mode in the future, follow the same procedure.
Restoring EEPROM and Flashing Firmware
First, restore the previously backed up EEPROM using Breed's web interface After EEPROM restoration, proceed to flash the OpenWrt firmware
Firmware information:
Management IP: 192.168.5.1 Default admin password: password WiFi SSID: openwrt WiFi password: password
Final Notes Due to the limited memory capacity of this router, installing additional packages may prove challenging. You may ultimately need to revert to the official firmware for practical everyday use.