dd-wrt on the wavlink WL-WN570HA1?

Post new topic   Reply to topic    DD-WRT Forum Forum Index -> Ralink SoC based Hardware
Author Message
vwnut8392
DD-WRT Novice


Joined: 30 Apr 2018
Posts: 9

PostPosted: Thu Nov 28, 2019 10:25    Post subject: dd-wrt on the wavlink WL-WN570HA1? Reply with quote
Did some work on getting into the stock firmware on the wavlink WL-WN570HA1 outdoor wireless repeater. the stock firmware sucks it needs dd-wrt!

Code:
Router info
Brand:WAVLINK
Model:WL-WN570HA1
Target:ramips
Subtarget:mt76x8
Package architecture:mipsel_24kc
Bootloader:U-Boot
CPU:MediaTek MT7688ANCPU
Cores:1CPU
MHz:580Flash
MB:8RAM
MB:64Ethernet
100M ports:1
WLAN Hardware:MediaTek MT7688AN, MediaTek MT7610EWLAN 2.4GHz:b/g/n
WLAN 5.0GHz:a/n/ac
WLAN driver:mt76
Detachable Antennas:2
Serial:Yes
Serial connection parameters:57600 / 8N1


attached is the bootloader BIN. i got this from instructions from this site http://osmar.gonzal.us/rewriting-mt7628an-bootloader/. it seems all wavlink are the same if not similar if firmware.

This is a link to the decompressed stock firmware version 190220. https://drive.google.com/open?id=1uDa2pOXi-R2pY_gTNilZ2GmjprWVsnyr


Lastly i figured out a trick to enable telnet on port 2323. what needs to be done to enable it is go to http://192.168.10.1/webcmd.shtml. this is a hidden web page in the router. type "telnet" into the command box and apply. nothing will show up in the box below but it if you port scan the router afterwards you will see that port 2323 is now open. the default login is "admin" and the password is also "admin". hopefully this is enough information for someone to compile even a small light version of dd-wrt for this device because it is a rather powerful router thats cost effective and the stock firmware sucks.
Sponsor
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 7185
Location: Texas, USA

PostPosted: Thu Nov 28, 2019 11:28    Post subject: Reply with quote
https://openwrt.org/toh/hwdata/wavlink/wavlink_wl-wn570ha1

https://wiki.dd-wrt.com/wiki/index.php/Supported_Devices#Read_Me_First.21

Good luck. OpenWRT seems to support it, but you would likely have to donate a device and wait for BS to port it.

_________________
Official Forum Rules, Guidelines, and Helpful InformationFirmware FAQInstallation WikiWhere Do I Download Firmware?
DON'T use Chromium-based browsersRTFM/STFW - TL;DR is NOT an excuse. • Why Should I Care What Color the Bikeshed Is?
Please DO NOT PM me with questions; Ask in the forum.

---------------------------------------------------------

Linux User #377467 counter.li.org / linuxcounter.net
vwnut8392
DD-WRT Novice


Joined: 30 Apr 2018
Posts: 9

PostPosted: Thu Nov 28, 2019 11:30    Post subject: factory firmware Reply with quote
It appears that not all firmware versions have webcmd.shtml in it so here is the factory 190220 firmware for this access point. you can flash this to it right over the web interface, dont have to do anything fancy. its in my google drive in the link below.
https://drive.google.com/open?id=1PlySf2y8X1vHCdl4wZT8hUtIO4QxcmHw
vwnut8392
DD-WRT Novice


Joined: 30 Apr 2018
Posts: 9

PostPosted: Thu Nov 28, 2019 11:41    Post subject: Reply with quote
kernel-panic69 wrote:
https://openwrt.org/toh/hwdata/wavlink/wavlink_wl-wn570ha1

https://wiki.dd-wrt.com/wiki/index.php/Supported_Devices#Read_Me_First.21

Good luck. OpenWRT seems to support it, but you would likely have to donate a device and wait for BS to port it.


why would a device need to be donated? between what i have posted, what openWRT has done for the hardware/software there should be no problem for someone thats skilled in compiling dd-wrt to do this. i can provide any information and files from the ones i have right here. if anyone wants a dump of the actual flash i have equipment on hand here that i can extract it and post it up for them.

actually i just pulled a dump from the flash of one of them that had a water issue but i realized this one was flashed with a wonky copy of openWRT so the dump from that one is no good. i will have to pull the one thats in use right now and dump its flash. also im dumping these chips with an MCUmall GQ-4X4 programmer and an SOIC clip Smile. flash chip is GD25Q64C. it can be pulled and reinstalled fairly easy with a hot air soldering station and some steady hands.

If the flash dump of the one that was running openWRT could be helpful i will gladly post it up too. i had both 2.4G and 5G radios working in openWRT.
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 7185
Location: Texas, USA

PostPosted: Thu Nov 28, 2019 12:36    Post subject: Reply with quote
I guess if you want to be the guinea pig and be the first to find out if it bricks or if it works without it being tested by the developer. How do you think OpenWRT figured it out? Looking at pictures? Honestly, if you have OpenWRT working on it, then what's the boggle? I get it, but I don't get it. If I had the time to re-download 20+GB of source code and dive into another project.... but hey, feel free if you wish.
_________________
Official Forum Rules, Guidelines, and Helpful InformationFirmware FAQInstallation WikiWhere Do I Download Firmware?
DON'T use Chromium-based browsersRTFM/STFW - TL;DR is NOT an excuse. • Why Should I Care What Color the Bikeshed Is?
Please DO NOT PM me with questions; Ask in the forum.

---------------------------------------------------------

Linux User #377467 counter.li.org / linuxcounter.net
vwnut8392
DD-WRT Novice


Joined: 30 Apr 2018
Posts: 9

PostPosted: Thu Nov 28, 2019 19:48    Post subject: Reply with quote
kernel-panic69 wrote:
I guess if you want to be the guinea pig and be the first to find out if it bricks or if it works without it being tested by the developer. How do you think OpenWRT figured it out? Looking at pictures? Honestly, if you have OpenWRT working on it, then what's the boggle? I get it, but I don't get it. If I had the time to re-download 20+GB of source code and dive into another project.... but hey, feel free if you wish.


well having the ability to reflash the flash chip itself externally isnt an issue so bricking it is technically impossible because i can just remove the flash, erase it and flash it back to a stock BIN image and start over as long as i made a backup of it prior to any testing.

i dont like the openWRT interface. DD-WRT is better and more user friendly. luci interface sucks. im not sure how openWRT did it but they only had a basic installation for it without the luci interface and i installed it over U-boot, than once it was on the device i used SSH to setup networking and have it download/install luci separately. it didnt always work well though, sometimes the wireless radios would screw up and it needed rebooted and over all the stock firmware could see more on a wireless scan than openWRT could. openWRT lacks the ability to fine tune the wifi radio or radios specifically and DD-wrt does do that. i want that feature so i can put different antennas on this device and be able to adjust x-mit to compensate for the different antennas.
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 7185
Location: Texas, USA

PostPosted: Thu Nov 28, 2019 22:40    Post subject: Reply with quote
Yes, I'm sure there's no nvram variables to tinker with in OpenWRT. Well, I guess you could email BrainSlayer with all the information or register and open a ticket. Don't expect it to happen overnight. There's still open tickets for feature requests and device support that go back several years....
_________________
Official Forum Rules, Guidelines, and Helpful InformationFirmware FAQInstallation WikiWhere Do I Download Firmware?
DON'T use Chromium-based browsersRTFM/STFW - TL;DR is NOT an excuse. • Why Should I Care What Color the Bikeshed Is?
Please DO NOT PM me with questions; Ask in the forum.

---------------------------------------------------------

Linux User #377467 counter.li.org / linuxcounter.net
vwnut8392
DD-WRT Novice


Joined: 30 Apr 2018
Posts: 9

PostPosted: Thu Nov 28, 2019 23:18    Post subject: Reply with quote
im looking into trying to do it myself and i dont know where to start honestly. seems like so many different ways to do it but only one way will work. i mean if he would consider doing it i'll provide whatever is needed here without a doubt. i think i've already covered most everything needed aside from the stock flash dump of the OEM firmware from the one working AP. correct me if im wrong but getting the flash dump is as good as if not better than having decompressed firmware from the BIN file right?

i do a lot of automotive ECU reverse engineering which is a bit different from this. car ECU's dont have compression on their BIN files so when we get a dump from the flash we can just load it into IDA pro and go. as for modifications to it we can just edit the code right in IDA if need be to check if its flowing correctly than export the new BIN and flash it right back into the car. in the car world our toughest feat is getting around the flash and eeprom protection placed by the ECU manufacturer because they do not want us messing with the software for performance reasons let along in the right hands firmware can be modified to bypass things like govt mandated emissions control crap. anyhow im lost with all of this dd-wrt development stuff. its nothing like what im used to seeing or working with, its a whole new learning curve.
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 7185
Location: Texas, USA

PostPosted: Fri Nov 29, 2019 0:47    Post subject: Reply with quote
With modern car control systems, I find it kinda hard to believe there is no file compression. Nav systems using QNX do have file system compression, otherwise, it wouldn't work. But hey, if you say so.

Yes, sorting through 20+GB of source code to figure out what is what, especially when the public repository is questionable, yeah, good luck.

_________________
Official Forum Rules, Guidelines, and Helpful InformationFirmware FAQInstallation WikiWhere Do I Download Firmware?
DON'T use Chromium-based browsersRTFM/STFW - TL;DR is NOT an excuse. • Why Should I Care What Color the Bikeshed Is?
Please DO NOT PM me with questions; Ask in the forum.

---------------------------------------------------------

Linux User #377467 counter.li.org / linuxcounter.net
vwnut8392
DD-WRT Novice


Joined: 30 Apr 2018
Posts: 9

PostPosted: Fri Nov 29, 2019 1:05    Post subject: Reply with quote
i mean yeah the devices like the multimedia interfaces have compressed operating systems but those are not my target. i work on the ECU itself directly and in a lot of new audi's for example the TCU (transmission computer) for performance applications. like the infineon tricore processor based ECU's dont use a compressed file system along with any of its predecessors. flash file size just keeps getting bigger. i would think eventually there will be compression on them as they are up to 4mb in size on average now. hopefully that happens long after im out of this game and i dont care about it.

how to i go about submitting a ticket for this? can you point me in the right direction with a link?
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 7185
Location: Texas, USA

PostPosted: Fri Nov 29, 2019 4:18    Post subject: Reply with quote
Where it says, "Bugtracker" on this page. ^^^^^ Upper left.

I'm surprised with a 4mb binary size that those ECUs and TCUs aren't compressed images, but again, not surprised. They have to be read fairly quickly, and I don't think they have any kind of RAM involved?

_________________
Official Forum Rules, Guidelines, and Helpful InformationFirmware FAQInstallation WikiWhere Do I Download Firmware?
DON'T use Chromium-based browsersRTFM/STFW - TL;DR is NOT an excuse. • Why Should I Care What Color the Bikeshed Is?
Please DO NOT PM me with questions; Ask in the forum.

---------------------------------------------------------

Linux User #377467 counter.li.org / linuxcounter.net
vwnut8392
DD-WRT Novice


Joined: 30 Apr 2018
Posts: 9

PostPosted: Fri Nov 29, 2019 7:20    Post subject: Reply with quote
kernel-panic69 wrote:
Where it says, "Bugtracker" on this page. ^^^^^ Upper left.

I'm surprised with a 4mb binary size that those ECUs and TCUs aren't compressed images, but again, not surprised. They have to be read fairly quickly, and I don't think they have any kind of RAM involved?


there is RAM in there too. some of these actually have RAM and RAM mirror. its strange the layout of a lot of these honestly.

Here is the Flash dump of 190200 firmware for this router.
vwnut8392
DD-WRT Novice


Joined: 30 Apr 2018
Posts: 9

PostPosted: Fri Dec 13, 2019 22:42    Post subject: Reply with quote
wow, no interest in this at all. interesting. its a 40.00 route/AP thats dual radio and really powerful plus waterproof so it can be used outdoor. i'd say its the best over all router of 2019.
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Forum Index -> Ralink SoC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum