Ethical Hacking Automation

Automate Recon and scanning process with Vidoc. All security teams in one place

Xiaomi Wireless Router Admin Panel - Detect

By kannthu

Informative
Vidoc logoVidoc Module
#panel#xiaomi
Description

What is the "Xiaomi Wireless Router Admin Panel - Detect?"

The "Xiaomi Wireless Router Admin Panel - Detect" module is designed to detect the presence of the Xiaomi Wireless router admin panel. This module focuses on identifying the specific software used for managing Xiaomi wireless routers. It is an informative module that helps users identify potential vulnerabilities or misconfigurations in their Xiaomi router admin panel.

This module has an informative severity level, which means it provides valuable information without indicating any immediate security risks.

Author: lu4nx

Impact

This module does not have any direct impact on the system or network being scanned. It solely focuses on detecting the presence of the Xiaomi Wireless router admin panel.

How does the module work?

The module works by sending an HTTP GET request to the "/cgi-bin/luci/web" path of the target device. It then applies two matching conditions to determine if the Xiaomi Wireless router admin panel is present:

    - The module checks the response body for the presence of the "" or "" HTML tags. If either of these tags is found, it indicates the presence of the Xiaomi Wireless router admin panel. - The module also checks if the HTTP response status code is 200, indicating a successful request. This condition ensures that the target device is accessible and responsive.

If both matching conditions are met, the module reports the detection of the Xiaomi Wireless router admin panel.

Example HTTP request:

GET /cgi-bin/luci/web

Matching conditions:

- Response body contains either "" or "" - HTTP response status code is 200

For more information, you can refer to the Xiaomi website.

Metadata:

- max-request: 1 - shodan-query: http

Module preview

Concurrent Requests (1)
1. HTTP Request template
GET/cgi-bin/luci/web
Matching conditions
word: <title>小米路由器</title>, <title>Redmi路由器</t...and
status: 200
Passive global matcher
No matching conditions.
On match action
Report vulnerability