🔬 固件安全审计报告

固件版本:PanabitOEM_TANGr7p8_20260414_Linux3样本文件:/tmp/panabit_pkg/PanabitOEM_TANGr7p8_20260414_Linux3扫描时间:2026-04-22 00:53:43检出组件:0 个外连域名:30 个

📊 风险评估

风险评分:0 / 100(低风险)

📑 目录

📋 执行摘要

本报告对固件 /tmp/panabit_pkg/PanabitOEM_TANGr7p8_20260414_Linux3 进行了安全审计。未发现严重安全问题。检测到 30 个外连域名138 个公网 IP

🔍 安全发现

🌐 已知外连目标

域名风险分类引用
report.url.cn🔴 hightelemetry
1 个文件
  • /bin/dpi.so
api.ngrok.cc🟡 mediumapi
1 个文件
  • /bin/dpi.so
api.duapp.com🟡 mediumapi
1 个文件
  • /bin/dpi.so
api.playstation.com🟡 mediumapi
1 个文件
  • /bin/dpi.so
stun.remotepc.com🟡 mediumnetwork
1 个文件
  • /bin/dpi.so
account.xyaz.cn🟡 mediumauth
1 个文件
  • /bin/dpi.so
auth.natapp.cn🟡 mediumauth
1 个文件
  • /bin/dpi.so
update.yjwujian.cn🟡 mediumupdate
1 个文件
  • /bin/dpi.so
cloud.dhgs.net🟡 mediumcloud
1 个文件
  • /bin/dpi.so
darwin.qianxin.com🟡 mediumsystem
1 个文件
  • /app/webui/bin/redirect_qax_download
api.epicgames.dev🟡 mediumapi
1 个文件
  • /bin/dpi.so
login.microsoftonline.com🟡 mediumauth
1 个文件
  • /bin/dpi.so
cloud.huawei.com🟡 mediumcloud
1 个文件
  • /bin/dpi.so
stun.workslink.com🟡 mediumnetwork
1 个文件
  • /bin/dpi.so
api.onedrive.com🟡 mediumapi
1 个文件
  • /bin/dpi.so
api.weipan.com🟡 mediumapi
1 个文件
  • /bin/dpi.so
ws.126.net🟡 mediumcloud
1 个文件
  • /bin/dpi.so
api.bminer.me🟡 mediumapi
1 个文件
  • /bin/dpi.so
login.live.com🟡 mediumauth
1 个文件
  • /bin/dpi.so
update.hihonorcdn.com🟡 mediumupdate
1 个文件
  • /bin/dpi.so
cloud.xylink.com🟡 mediumcloud
1 个文件
  • /bin/dpi.so
obj.data.id🟢 lowunknown
56 个文件
  • /admin/html/auth/dot1x_rule_list.html
  • /admin/html/auth/l2bypass_svrlist.html
  • /admin/html/auth/pppoesvr_list.html
  • /admin/html/common/select_acct.html
  • /admin/html/common/select_app.html
  • /admin/html/common/select_dnsgrp.html
  • /admin/html/common/select_ippool.html
  • /admin/html/common/select_iptab.html
  • /admin/html/common/select_proxy.html
  • /admin/html/common/select_ugroup.html
  • /admin/html/control/conlimit_list.html
  • /admin/html/control/malc_dbtype.html
  • /admin/html/control/malc_vendor.html
  • /admin/html/dashboard/item_proxy_list.html
  • /admin/html/flowcontrol/acl_list.html
  • /admin/html/flowcontrol/flowct_list.html
  • /admin/html/flowcontrol/nflowct_list.html
  • /admin/html/flowcontrol/ntmso_list.html
  • /admin/html/flowschedu/policy_list.html
  • /admin/html/monitor/ipobj_list_tree.html
  • /admin/html/monitor/ipview_mobile.html
  • /admin/html/network/dhcpsvr_list.html
  • /admin/html/network/dhcpsvr_v6_list.html
  • /admin/html/network/iwan_server_list.html
  • /admin/html/network/iwan_user_list.html
  • /admin/html/network/lan_list.html
  • /admin/html/network/switch_vlan_list.html
  • /admin/html/network/wan_list.html
  • /admin/html/network/wangroup_addwan.html
  • /admin/html/network/wangroup_get.html
  • /admin/html/network/wangroup_manager.html
  • /admin/html/object/file_type_list.html
  • /admin/html/object/glink_stat.html
  • /admin/html/object/iptab_list.html
  • /admin/html/object/rtptime_list.html
  • /admin/html/object/urlgrp_list.html
  • /admin/html/object/user_group_list.html
  • /admin/html/object/usertab_list.html
  • /admin/html/object/vlink_list.html
  • /admin/html/protection/attackpro_list.html
  • /admin/html/proto/url_cat.html
  • /admin/html/route/portmap_list.html
  • /admin/html/route/route6_policy_list.html
  • /admin/html/route/server_group.html
  • /admin/html/route/server_list.html
  • /admin/html/route/static_nat_list.html
  • /admin/html/route/urlmap_list.html
  • /admin/html/sac/crontab_list.html
  • /admin/html/sac/ssid_list.html
  • /admin/html/system/sys_check_ping_add.html
  • /admin/html/system/webuser_online.html
  • /admin/html/warring/alert_evt_cur_list.html
  • /admin/html/warring/alert_evt_end_card.html
  • /admin/html/warring/alert_evt_end_list.html
  • /admin/html/warring/alert_host_group.html
  • /admin/html/warring/internet_api.html
download.panabit.com🟢 lowupdate
14 个文件
  • /admin/cgi-bin/sac/ajax_sac_ap
  • /admin/cgi-bin/system/ajax_app_store
  • /admin/html/common/layout_head.html
  • /admin/html/control/malc_history.html
  • /admin/html/control/malc_log.html
  • /admin/html/control/malc_vendor.html
  • /admin/html/monitor/ipview_malc.html
  • /admin/html/system/app_cloud.html
  • /admin/html/system/sys_upgrade_auto.html
  • /app/webui/bin/check_apupgrade
  • /app/webui/bin/install_tool
  • /app/webui/bin/pa_malc_sync
  • /app/webui/bin/system_news_check
  • /bin/download
obj.field.id🟢 lowunknown
7 个文件
  • /admin/html/control/malc_dbedit.html
  • /admin/html/object/iptab_list.html
  • /admin/html/object/urlgrp_list.html
  • /admin/html/object/usertab_list.html
  • /admin/html/route/domain_policy_add.html
  • /admin/html/route/static_nat_add.html
  • /admin/html/sac/crontab_add.html
json.data.info🟢 lowunknown
5 个文件
  • /admin/html/monitor/interface_set.html
  • /admin/html/object/user_group_add.html
  • /admin/html/proto/appview_config.html
  • /admin/html/route/static_nat_add.html
  • /admin/html/sac/ap_group_list.html
www.panabit.com🟢 lowfrontend
5 个文件
  • /admin/html/common/layout_body.html
  • /admin/html/common/layout_head.html
  • /admin/html/common/login.js
  • /app/_app_install/motd
  • /bin/ipe_msgpush
ti.qianxin.com🟢 lowunknown
4 个文件
  • /admin/html/control/malc_history.html
  • /admin/html/control/malc_log.html
  • /admin/html/control/malc_vendor.html
  • /admin/html/monitor/ipview_malc.html
obj.data.app🟢 lowunknown
4 个文件
  • /admin/html/network/pxyview_topapp.html
  • /admin/html/system/app_cloud.html
  • /admin/html/system/app_local.html
  • /admin/html/system/sys_upgrade_auto.html
d.data.id🟢 lowunknown
2 个文件
  • /admin/html/flowcontrol/acl_list.html
  • /admin/html/flowcontrol/nflowct_list.html
weixin.panabit.com🟢 lowunknown
2 个文件
  • /admin/html/warring/internet_api.html
  • /bin/ipe_msgpush

📍 已知服务器 IP

IP 地址说明
183.255.234.491 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
183.255.234.81 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
183.255.234.91 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
61.241.63.1751 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
139.189.127.751 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
183.255.124.461 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
183.255.234.521 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
119.147.89.2451 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
183.255.124.271 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
183.255.234.331 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
183.255.234.341 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
183.255.234.431 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
183.255.124.81 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
183.255.124.201 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
183.255.234.581 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
183.255.234.601 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
183.255.234.621 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
183.255.234.351 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
183.255.234.151 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com
183.255.124.181 个文件 → vcinema.com.cn, bn.netease.com, server.crossloop.com

🔍 代码行为分析

发现 34 个网络调用

操作类型目标文件代码
connectnetcatdec.tar.gz/admin/cgi-bin/flowcontrol/ajax_malc:281errmsg=`openssl enc -aes-256-cbc -d -salt -md sha256 -k "${channel_key}" -in "${...
POST/uploadxhrhttp://www.w3.org/2000/svg/admin/html/assert/layui.all.js:1/** v2.13.0 | MIT Licensed */;!function(d){"use strict";var e,h=d.document,v=d.l...
POST/uploadxhrhttps://xxxx/VPATH_test//admin/html/assert/panabit.js:1var cLang = { "LANG0001": {"ch": "ȷ��", "en": "OK"}, "LANG0002": {"ch": "����",...
POST/uploadxhrhttps://www.panabit.com/admin/html/common/login.js:1if (window.top != window.self) parent.location.href = "../login/login.cgi?t=v"; ...
GETjqueryd.src.length/admin/html/control/malc_auth.html:1{{# var lang003 = {"ch": "����", "en": "Any"}, lang004 = {"ch": "��־����", ...
GETjqueryhttps://download.panabit.com/admin/html/control/malc_history.html:1{{# var lang003 = {"ch": "����", "en": "Any"}, lang004 = {"ch": "��־����", ...
POST/uploadjqueryjson.data.length/admin/html/control/malc_report.html:1{{# var lang003 = {"ch": "����", "en": "Any"}, lang004 = {"ch": "��־����", ...
GETjqueryobj.data.ip/admin/html/control/malc_user.html:1{{# var lang001 = {"ch": "�����û�", "en": "Hit User"}, lang002 = {"ch"...
GETjqueryd.dst.length/admin/html/control/malc_username.html:1{{# var lang003 = {"ch": "����", "en": "Any"}, lang004 = {"ch": "��־����", ...
uploaduploadhttps://download.panabit.com/admin/html/control/malc_vendor.html:1{{# var lang001 = {"ch": "�鱨�ſ�", "en": "Intelligence Overview"}, lan...
GETjqueryobj.data.proto/admin/html/monitor/ipview_tunnel.html:1{{# var lang001 = {"ch": "ԴIP", "en": "Src IP"}, lang002 = {"ch": "Դ��...
GETjqueryobj.data.ip/admin/html/proto/appview_flow.html:1{{# var lang001 = {"ch": "�û�����", "en": "User Direction"}, lang002 = {"ch": "...
GETjqueryobj.data.ip/admin/html/proto/appview_user.html:1{{# var lang001 = {"ch": "�ؼ�������", "en": "Search"}, lang002 = {"ch": "���",...
uploaduploadjson.data.deduppkt/admin/html/proto/dpi_config.html:1{{# var lang001 = {"ch": "�������", "en": "DPI Engine Settings"}, lang002 = {"c...
uploaduploadd.sortver.split/admin/html/sac/ap_set_upgrade.html:1{{# var lang001 = {"ch": "�豸��Ϣ", "en": "Device Info"}, lang002 = {"ch": "��...
uploaduploadjson.data.ifadmin/admin/html/system/sys_setting_web.html:1{{# var lang001 = {"ch": "WEB����", "en": "Web Access"}, lang002 = {"ch": "�����...

⚠️ 审计结论

检测到 30 个外连域名。

建议:审查所有外连通信,更换默认凭据,升级过时的加密库。