eATM

小米CR880X开启telenet

开启:http://192.168.3.7/cgi-bin/luci/;stok=91a4a2bb9f1663078e0fc5ec11eadddd/api/misystem/set_telnet?enable=1

查看: http://192.168.3.7/cgi-bin/luci/;stok=99bda34ee768d74282ae25ed02886335/api/misystem/get_telnet

用户名:root  密码:路由器后面贴的默认登录密码:w38eehct

密码不对的话看这个mgtpsd值: http://192.168.3.7/cgi-bin/luci/api/xqsystem/bdata

一键脚本开启:

function handle_error(obj) {
    //{"code":401,"msg":"Invalid token"}
    if (obj.code != 0) {
        alert("发生错误,需要刷新页面:\r\n" + JSON.stringify(obj, null, 4))
        throw new Error('发生错误');
    }
}
const base_url=(function() {
    var currentUrl = document.URL;
    var stok = currentUrl.match(/stok=(\S*)\/web/)[1];
    var host = window.location.hostname + (window.location.port ? ':' + window.location.port : '');
    let url = "http://" + host + "/cgi-bin/luci/;stok=" + stok + "/"
    return url;
})();

function get_telnet() {
    let url = base_url + "api/misystem/get_telnet";
    let ret;
    $.ajax({
        url: url,
        async: false,//同步方式发送请求,true为异步发送
        type: "GET",
        dataType: "json",
        data: {},
        success: function (result) {
            handle_error(result)
            ret = result.enable;
        }
    });
    return ret;
}

function enable_telnet() {
    if (get_telnet() == 1) return true;

    let ret = false;

    let url = base_url + "api/misystem/set_telnet?enable=1";
    $.ajax({
        url: url,
        async: false,//同步方式发送请求,true为异步发送
        type: "GET",
        dataType: "json",
        data: {},
        success: function (result) {
            handle_error(result)
            ret = true;
        }
    });
    return ret;
}

//得到登录密码
function get_password()
{
    let url = base_url + "api/xqsystem/bdata";
    let ret;
    $.ajax({
        url: url,
        async: false,//同步方式发送请求,true为异步发送
        type: "GET",
        dataType: "json",
        data: {},
        success: function (result) {
            ret = result.mgtpsd;
        }
    });
    return ret;
}

enable_telnet();
let pwd=get_password();

alert("开启telnet成功:"+document.location.host+"\r\n用户:root\r\n密码:"+pwd);

 

 

#开启SSH

#打开调试模式来解除 bdata 的写保护
zz=$(dd if=/dev/zero bs=1 count=2 2>/dev/null) ; printf '\xA5\x5A%c%c' $zz $zz | mtd write - crash

#重启
reboot

#修改数据
bdata set ssh_en=1
bdata set telnet_en=1
bdata set uart_en=1
bdata set boot_wait=on
bdata commit

#重启
reboot

#恢复写保护
mtd erase crash

#重启
reboot

#查看bdata设置
bdata show




 

 

 

参考:https://www.right.com.cn/forum/thread-8364521-1-1.html

发表回复

您的电子邮箱地址不会被公开。 必填项已用*标注