Help flashed Asus FW to R8000, now bricked

Post new topic   Reply to topic    DD-WRT Forum Forum Index -> Broadcom SoC based Hardware
Goto page Previous  1, 2, 3, 4  Next
Author Message
Galactus
DD-WRT Novice


Joined: 22 Oct 2019
Posts: 14

PostPosted: Fri Feb 21, 2020 9:06    Post subject: Reply with quote
So, after finally finding some to time to desolder the pain in the arse heatsink, I annoyingly find my nand chip in my R8000 isn't Macronix brand but Spansion as shown in bottom left of picture attached.

Interstingly though there is some kind of header to the right of that Spansion nand chip, can anyone confirm it could be a JTAG header?

I've found some details about the Spansion chip pinouts I'll post shortly for future reference for anyone in dire need.

Hopefully I can look at shorting some pins to force it back into TFTP recovery so I can get a ping back from the ETH interfaces.



photo_2020-02-21_08-50-07rs.jpg
 Description:
 Filesize:  99.02 KB
 Viewed:  4029 Time(s)

photo_2020-02-21_08-50-07rs.jpg




Last edited by Galactus on Fri Feb 21, 2020 9:29; edited 2 times in total
Sponsor
Galactus
DD-WRT Novice


Joined: 22 Oct 2019
Posts: 14

PostPosted: Fri Feb 21, 2020 9:17    Post subject: Reply with quote
Spansion Nand chip pinout details attached.

S34ML01G200TF100
552BB697 A



002-00499_s34ml01g2_s34ml02g2_s34ml04g2_1_gb_2_gb_4_gb_3_v_4-bit_ecc_slc_nand_flash_memory_for_embedded.pdf
 Description:

Download
 Filename:  002-00499_s34ml01g2_s34ml02g2_s34ml04g2_1_gb_2_gb_4_gb_3_v_4-bit_ecc_slc_nand_flash_memory_for_embedded.pdf
 Filesize:  7.19 MB
 Downloaded:  151 Time(s)

Galactus
DD-WRT Novice


Joined: 22 Oct 2019
Posts: 14

PostPosted: Fri Feb 21, 2020 9:23    Post subject: Reply with quote
Here is Magnetron1.1 kindly provided picture of the R8000 MB featuring the Matronix Nand chip to compare with the Spansion Nand chip from my R8000 posted above for reference.


R8K-Top-View-SystemPCB-Without-Heatsink-And-EMI_CoversRS1.JPG
 Description:
 Filesize:  86.92 KB
 Viewed:  4028 Time(s)

R8K-Top-View-SystemPCB-Without-Heatsink-And-EMI_CoversRS1.JPG


Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 5009
Location: UK, London, just across the river..

PostPosted: Fri Feb 21, 2020 11:30    Post subject: Reply with quote
https://forum.dd-wrt.com/phpBB2/viewtopic.php?p=905204#905204 yep on this link, you've shared...there are pretty clear instructions, how to serial flash that buddy (R8000)...even if CFE is corrupted there is a 'how to' ... i do not poses this router, and i do not know any other ways than TFTP flash or serial recovery, to recover a bricked unit...
usually CFE could be corrupted or bad flash, like flashing something else or hardware failure...or dead capacitor...try to explore those options first...

also do keep in mind those instructions from the link above, date back in 2014 so, use a build from that era could be a plus, once up and running you could update to a most recent...


all R series Netgears have a tftp

https://kb.netgear.com/000059633/How-to-upload-firmware-to-a-NETGEAR-router-using-TFTP-client

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 48646 WAP
TP-Link WR1043NDv2 -DD-WRT 48865 Gateway,DNS,AP Isolation,Ad-Block,Firewall,Forced DNS,DoT,VPN,VLAN
TP-Link WR1043NDv2 -DD-WRT 48886 Gateway,DNS,Ad-Block,Firewall,Forced DNS,DoT,VPN,VLAN
TP-Link WR1043NDv2 -Gargoyle OS 1.13.0b AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear R7800 --DD-WRT 48886 Gateway,DNS,AD-Block,AP&Net Isolation,VLAN's,Firewall,DoT,Vanilla
Netgear R9000 --DD-WRT 48886 Gateway,DNS,AD-Block,AP Isolation,Firewall,Forced DNS,DoT,2,4Ghz only,Vanilla
Broadcom
Netgear R7000 ---DD-WRT 48886 Gateway,DNS,AD-Block,Firewall,Forced DNS,VLAN's,DoT,VPN
------------------------------------------------------
Stubby for DNS over TLS I DNSCrypt v2 by mac913
Malachi
DD-WRT Guru


Joined: 17 Jul 2012
Posts: 7209
Location: Columbus, Ohio

PostPosted: Fri Feb 21, 2020 12:52    Post subject: Reply with quote
He can’t flash it using serial because it stops at waiting for reset button release. It never gets to the point we’re he can stop the cfe and flash using tftp.
The only recourse is probably desoldering the chip, reprogramming and soldering it back on.

_________________
I am far from a guru, I'm barely a novice.
Galactus
DD-WRT Novice


Joined: 22 Oct 2019
Posts: 14

PostPosted: Fri Feb 21, 2020 12:59    Post subject: Reply with quote
Cheers for the feedback Alozaros, problem I've got is tftp is toast. I get a network link light but no ping.

Tried a network sniffer so nothing seems to be responding on the ethernet interfaces.

I'm facing the exact same issue as the thread starter.

Basically from bad advice from a reddit thread which I linked earlier in this thread. I installed what I thought was an updated netgear r8000 AC3200 which turned out to be an ASUS RT-AC3200 firmware.
My own very stupid mistake.

So although it boots and I can see CFE loading in Xterm, I cant break into it with CTRL-C so having to take the drastic option as I'm getting Waiting for wps button release... which I guess has caused GPIO to reroute for the WLAN button.

Holding downing any and all button sequences (Reset, WLAN, WPS) doesnt halt the CFE boot.



CFE version 7.14.43.40 (r527781) based on BBP 1.0.37 for BCM947XX (32bit,SP,)
Build Date: Fri Aug 11 08:07:07 CST 2017 (defjovi@ubuntu-eva01)
Copyright (C) 2000-2008 Broadcom Corporation.

Init Arena
Init Devs.
Boot partition size = 262144(0x40000)
DDR Clock: 400 MHz
Info: DDR frequency set from clkfreq=1000,*800*
Warning: invalid DDR setting of 800 MHz ignored. DDR frequency will be set to 400 MHz.
CPU type 0x0: 1000MHz
Tot mem: 262144 KBytes

CFE mem: 0x00F00000 - 0x017A7270 (9073264)
Data: 0x00F4F834 - 0x00F4FD74 (1344)
BSS: 0x00F4FD80 - 0x00FA5270 (349424)
Heap: 0x00FA5270 - 0x017A5270 (8388608)
Stack: 0x017A5270 - 0x017A7270 (8192)
Text: 0x00F00000 - 0x00F45D7C (286076)

Committing NVRAM...done
Waiting for wps button release...
Galactus
DD-WRT Novice


Joined: 22 Oct 2019
Posts: 14

PostPosted: Fri Feb 21, 2020 13:13    Post subject: Reply with quote
Just came across these threads today from Koolshare Chinese Asus/Negear forum of someone having a similar ballache to me, although its for a R7000 router which isnt too dissimilar, the user has ended up with the same situation of waiting for WPS button release from install asus merlin firmware on his R7000.

Using google chrome to translate so hopefully I can make something out of this guys support which looks promising although, a lot of it is lost in translation..heh

https://koolshare.cn/thread-159101-1-1.html
https://koolshare.cn/thread-136346-1-1.html
https://koolshare.cn/thread-148875-1-1.html
Galactus
DD-WRT Novice


Joined: 22 Oct 2019
Posts: 14

PostPosted: Fri Feb 21, 2020 13:26    Post subject: Reply with quote
Any of you guys have any idea what this could be in red next to the nand chip?


photo_2020_02_21_08_50_07r.jpg
 Description:
 Filesize:  90.56 KB
 Viewed:  3971 Time(s)

photo_2020_02_21_08_50_07r.jpg


Malachi
DD-WRT Guru


Joined: 17 Jul 2012
Posts: 7209
Location: Columbus, Ohio

PostPosted: Fri Feb 21, 2020 16:07    Post subject: Reply with quote
I’ve had the waiting for reset a few times.
Those look like jtag but there is no jtag support for the chip.

It’s not because of the ASUS firmware.
I’ve had it on r7000 that and wndr4500 that had been running netgear and/or dd-wrt.

Usually the boot process is stopped after the waiting fir reset button release point.
I have no idea why. I’ve unbricked dozens and dozens and dozens of routers using serial, maybe more, so I know how to do it.

_________________
I am far from a guru, I'm barely a novice.
Galactus
DD-WRT Novice


Joined: 22 Oct 2019
Posts: 14

PostPosted: Mon Feb 24, 2020 11:28    Post subject: Reply with quote
CFE has been replaced by the asus version as shown here instead of the Foxconn cfe loader. (RT-AC3200) A mess from running a modified rt-ac3200 based merlin asus firmware for the R8000.

I used if for a long while for openvpn client support, until later finding DD-WRT supports it also.....toooo late.

Can't find asus minicfe either. I get eth link connection but no DHCP. Statically assining ip's on my pc for various ip subnets finds no listening ports.
Galactus
DD-WRT Novice


Joined: 22 Oct 2019
Posts: 14

PostPosted: Mon Feb 24, 2020 11:30    Post subject: Reply with quote
ASUS Merlin Based CFE

CFE version 7.14.43.40 (r527781) based on BBP 1.0.37 for BCM947XX (32bit,SP,)
Build Date: Fri Aug 11 08:07:07 CST 2017 (defjovi@ubuntu-eva01)
Copyright (C) 2000-2008 Broadcom Corporation.

Init Arena
Init Devs.
Boot partition size = 262144(0x40000)
DDR Clock: 400 MHz
Info: DDR frequency set from clkfreq=1000,*800*
Warning: invalid DDR setting of 800 MHz ignored. DDR frequency will be set to 400 MHz.
CPU type 0x0: 1000MHz
Tot mem: 262144 KBytes

CFE mem: 0x00F00000 - 0x017A7270 (9073264)
Data: 0x00F4F834 - 0x00F4FD74 (1344)
BSS: 0x00F4FD80 - 0x00FA5270 (349424)
Heap: 0x00FA5270 - 0x017A5270 (8388608)
Stack: 0x017A5270 - 0x017A7270 (8192)
Text: 0x00F00000 - 0x00F45D7C (286076)

Committing NVRAM...done
Waiting for wps button release...
Galactus
DD-WRT Novice


Joined: 22 Oct 2019
Posts: 14

PostPosted: Mon Feb 24, 2020 11:31    Post subject: Reply with quote
R8000 Netgear Standard CFE


after erasing nvram.png
 Description:
 Filesize:  22.85 KB
 Viewed:  3080 Time(s)

after erasing nvram.png


Galactus
DD-WRT Novice


Joined: 22 Oct 2019
Posts: 14

PostPosted: Mon Feb 24, 2020 11:39    Post subject: Reply with quote
I can see they're almost identical hardware between the two.

http://en.techinfodepot.shoutwiki.com/wiki/Netgear_R8000

http://en.techinfodepot.shoutwiki.com/wiki/ASUS_RT-AC3200
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 12456
Location: Texas, USA

PostPosted: Mon Feb 24, 2020 13:34    Post subject: Reply with quote
Looks like stock CFE was able to be broken before the WPS button entry to me. Not sure how that affects things, but if Malachi says it's done, it's done. Only thing I can think of is to try and re-flash the Merlin firmware and then revert to stock from there, if you can even get it to accept a flash, but I think we already covered that you can't. Looks like you have a paperweight unless you can clickity-clack CTRL+C quick enough to break CFE boot.
_________________
Official Forum Rules, Guidelines & Helpful InformationFirmware FAQInstallation WikiWhere Do I Download Firmware‽
DON'T use Chromium-based browsersRTFM/STFW TL;DR is NOT an excuse. • Why Should I Care What Color the Bikeshed Is‽
Please DO NOT PM me with questions; Ask in the forum. ---------------------- Linux User #377467 counter.li.org / linuxcounter.net
Galactus
DD-WRT Novice


Joined: 22 Oct 2019
Posts: 14

PostPosted: Mon Feb 24, 2020 13:45    Post subject: Reply with quote
Yep, looking more and more like a big paperweight. I have one of these somewhere, may try give it a go. Used it a while back for a inline playstation recovery using a chip press-on adapter to recover nand. Was a headache but worked. Saved the impossible task of desoldering the nand chip.

https://www.embeddedcomputers.net/products/FlashcatUSB_XPORT/
Goto page Previous  1, 2, 3, 4  Next Display posts from previous:    Page 2 of 4
Post new topic   Reply to topic    DD-WRT Forum Forum Index -> Broadcom SoC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum