๐Ÿ”ฌ Nyarc Security Audit Report

Firmware: OpenWrt 18.06-SNAPSHOT unknownSample: /tmp/xiaomi-test/rootfsSize: 88.1MBScan Date: 2026-04-22 00:31:29Components: 0 foundDomains: 30 tracked

๐Ÿ“Š Risk Summary

๐Ÿ”ด 1 CRITICAL๐ŸŸก 1 MEDIUM

๐Ÿ” Detailed Findings

๐Ÿ” Authentication

User 'root' uses MD5crypt weak hash MEDIUM
MD5crypt ($1$) is a weak algorithm, recommend migration to SHA-512 ($6$)
/etc/shadow: root:$1$MULfKgY6$rdJYoUcz...

๐Ÿ“ฆ Crypto Libraries

OpenSSL 1.0.0 โ€” End of Life CRITICAL
OpenSSL 1.0.x reached EOL in 2020. Contains numerous known CVEs including potential RCE
/usr/lib/libssl.so.1.0.0

๐ŸŒ Known Outbound Connections

DomainPortUsageComponent
log.miwifi.comhightelemetry/etc/config/miwifi /usr/bin/matool
api.miwifi.commediumapi/etc/config/miwifi /etc/config/wifishare /etc/nginx/miwifi-webinitrd-https.conf /etc/nginx/miwifi-webinitrd.conf /lib/config_post_ota/wifishare_post_ota.sh /usr/bin/matool /usr/bin/messagingagent /usr/lib/lua/luci/view/web/init/guide.htm /usr/sbin/recovery_info_sync.sh /usr/sbin/wanip_check.sh /usr/sbin/wifishare.sh /www/self_diag/resource/js/helper.js /www/static/js/26.99691565a33a850fa3f9.js
bigota.miwifi.commediumupdate/usr/lib/lua/luci/view/web/inc/g.js.htm /usr/lib/lua/luci/view/web/init/bind.htm /usr/lib/lua/luci/view/web/init/guide.htm /usr/lib/lua/luci/view/web/sysauth.htm /usr/sbin/wifishare.sh /www/static/js/25.1bc67c9fea76d27c1a01.js
account.xiaomi.commediumauth/usr/lib/lua/luci/view/web/inc/agreement.htm /usr/lib/lua/luci/view/web/inc/agreement_HK.htm /usr/lib/lua/luci/view/web/inc/agreement_TW.htm /www/static/js/27.a6589dae1974c2685095.js
broker.miwifi.commediumcloud/etc/config/miwifi /usr/bin/matool /usr/bin/messagingagent
dlied6.qq.commediumsystem/usr/bin/download_speedtest /usr/bin/speedtest /usr/bin/upload_speedtest
push.apple.commediumcloud/etc/nginx/miwifi-webinitrd-https.conf /etc/nginx/miwifi-webinitrd.conf
stun.miwifi.commediumnetwork/etc/config/miwifi /usr/bin/matool
system.netdt.cnmediumsystem/usr/sbin/nettb /usr/sbin/pppoe-check
api.miwfi.commediumapi/usr/sbin/wanip_check.sh
www.miwifi.comlowfrontend/etc/init.d/dnsmasq /etc/nginx/miwifi-webinitrd-https.conf /etc/nginx/miwifi-webinitrd.conf /etc/nginx/nginx.conf /etc/rc.d/S19dnsmasq /usr/lib/lua/luci/view/web/inc/agreement.htm /usr/lib/lua/luci/view/web/inc/agreement_HK.htm /usr/lib/lua/luci/view/web/inc/agreement_TW.htm /usr/lib/lua/luci/view/web/inc/privacy_US_inter.htm /usr/sbin/sysapi.firewall /www/static/js/27.a6589dae1974c2685095.js
www.mi.comlowfrontend/usr/lib/lua/luci/view/web/inc/agreement.htm /usr/lib/lua/luci/view/web/inc/agreement_KR.htm /usr/lib/lua/luci/view/web/inc/agreement_TW.htm /usr/lib/lua/luci/view/web/inc/agreement_US.htm /usr/lib/lua/luci/view/web/inc/agreement_US_inter.htm /usr/lib/lua/luci/view/web/inc/g.js.htm /usr/lib/lua/luci/view/web/index.htm /usr/lib/lua/luci/view/web/init/guide.htm /usr/sbin/miniupnpd /www/static/js/27.a6589dae1974c2685095.js
app.miwifi.comlowapi/etc/config/miwifi /usr/lib/libpackagesign.so /usr/lib/libpackagesign.so.1 /usr/lib/libpackagesign.so.1.0.0 /usr/lib/opkg/info/packagesign.list /usr/sbin/installplugin /usr/sbin/pluginControllor /usr/sbin/plugincenter
s.miwifi.comlowcdn/etc/config/miwifi /etc/config/wifishare /etc/nginx/htdocs/wifishare.html /lib/config_post_ota/wifishare_post_ota.sh /usr/sbin/datacenter /usr/sbin/plugincenter /usr/sbin/wifishare.sh /www/v3.html
www1.miwifi.comlowfrontend/usr/lib/lua/luci/view/web/inc/footer.htm /usr/lib/lua/luci/view/web/inc/footermini.htm /usr/lib/lua/luci/view/web/inc/g.js.htm /usr/lib/lua/luci/view/web/inc/store.htm /usr/lib/lua/luci/view/web/init/guide.htm /usr/lib/lua/luci/view/web/sysauth.htm /usr/sbin/miniupnpd
oss.maxcdn.comlowcdn/www/self_diag/pages/custom.html /www/self_diag/pages/download.html /www/self_diag/pages/harddisk.html /www/self_diag/pages/index.html /www/self_diag/pages/usb.html /www/self_diag/pages/wireless.html
captive.apple.comlownetwork/etc/config/wifishare /etc/nginx/miwifi-webinitrd-https.conf /etc/nginx/miwifi-webinitrd.conf /lib/config_post_ota/wifishare_post_ota.sh /usr/sbin/wifishare.sh
wiki.openwrt.orglowdocs/usr/lib/opkg/info/6rd.control /usr/lib/opkg/info/ddns-scripts.control /usr/lib/opkg/info/ds-lite.control /usr/lib/opkg/info/map.control
itunes.apple.comlowfrontend/usr/lib/lua/luci/view/web/init/bind.htm /usr/lib/lua/luci/view/web/init/guide.htm /usr/lib/lua/luci/view/web/sysauth.htm /www/static/js/25.1bc67c9fea76d27c1a01.js
www.baidu.comlowfrontend/etc/config/system /etc/nginx/miwifi-webinitrd-https.conf /etc/nginx/miwifi-webinitrd.conf
freedns.42.pllowconfig/etc/ddns/services /etc/uci-defaults/ddns /etc/uci-defaults/ddns_no-ip_com
lists.balabit.hulowlibrary/usr/lib/libsyslog-ng-3.9.so.0 /usr/lib/libsyslog-ng-3.9.so.0.0.0 /usr/lib/libsyslog-ng.so
www.ascc.netlowfrontend/usr/lib/libxml2.so /usr/lib/libxml2.so.2 /usr/lib/libxml2.so.2.9.8
lysator.liu.selowlibrary/usr/lib/libssh2.so /usr/lib/libssh2.so.1 /usr/lib/libssh2.so.1.0.1
cshore.thecshore.comlowpackage/usr/lib/opkg/info/rp-pppoe-common.control /usr/lib/opkg/info/rp-pppoe-relay.control /usr/lib/opkg/info/rp-pppoe-server.control
www.balabit.comlowfrontend/usr/lib/libsyslog-ng-3.9.so.0 /usr/lib/libsyslog-ng-3.9.so.0.0.0 /usr/lib/libsyslog-ng.so
htp.miwifi.comlownetwork/etc/nginx/miwifi-webinitrd-https.conf /etc/nginx/miwifi-webinitrd.conf /usr/sbin/ntpsetclock
www.taobao.comlowfrontend/etc/config/system /usr/bin/upload_speedtest /usr/share/speedtest.xml
www.veracrypt.frlowfrontend/usr/lib/libgio-2.0.so /usr/lib/libgio-2.0.so.0 /usr/lib/libgio-2.0.so.0.5800.1
dyndns.regfish.delowconfig/etc/ddns/services /etc/ddns/services_ipv6

๐Ÿ“ Known Server IPs

61.135.92.128 (1 files)
61.135.106.128 (1 files)
18.244.0.188 (2 files)
183.84.5.44 (1 files)
58.83.177.108 (1 files)
54.85.90.122 (3 files)
61.135.91.128 (1 files)

โš ๏ธ VERDICT

Found 1 critical, 1 medium, 30 outbound domains detected.

Recommendation: Review all outbound connections, replace default credentials, upgrade deprecated crypto libraries.