Table of Contents

Buffalo WZR-D1800H - Truly unbricking!!!!

Introduction

Many on-line references are just plain wrong about this device. Pinout was wrong, information about the JTAG was wrong. Information about memory architecture was wrong. No clarification about what the buttons was complete.

This page comes as a hopeful clarifications to many missing or wrong information on the web on how to unbrick this device.

Prelude: How I broke my device: DD-WRT just plain wrong instructions.

DD-WRT has many places where some one can get the wrong idea of how to upgrade this device. Some problems:

Specific errors I made:

How it bricked

In the next sections I will describe what I tried and if you want to do yourself, you probably would like to try these things in this order. They more or less increase in complexity but also in possibility to success!

What I tried to recover from bricked

Factory Reset 30/30/30

I just must have to say that it did nothing.

After doing this I tried all the recovery methods: Pinging: nothing, TFTP recover: nothing, UART: nothing back, JTAG: not successful, several SPI ICs flashings: didn't matter.

TFTP

UART

JTAG

Info : JTAG tap: bcm4706.cpu tap/device found: 0x000c317f (mfg: 0x0bf (Broadcom), part: 0x00c3, ver: 0x0)

but this was possible only in irlen 32, what is apparently know as the Broadcom JTAG TAP controller and not the EJTAG MIPS Core space. Which is the real processor.

NAND and SPI flash shorting

Re-flashing the SPI

- The last resort. And everybody said it should work. But, there is a problem: you need a donor image. I couldn't find a donor image for exactl this device available on the web. The most similar one I found was for an Asus_RT-N66U-B1 also with a broadcom BCM4706 SoC device. The network devices were different. And this could be a problem. Later after many trials I asked with private messages directly to particular people on the dd-wrt forum and one nice Adrian answered. He sent me an image of the CFE for the exact same device. Just with one detail. For privacy and security concerns he sent me the file with the MAC addresses and other details edited. Which I totally understand. The problem: the checksums. - One of the first things I did was to get the SPI IC detected. The detection was not stable. But I was able to make a backup like this of my SPI IC. This I discovered possibly had reading corruption. - Later I discovered that reading twice from the SPI IC gave different results. Reason: noise on the lines, solution: 0.1uF capacitor between Vcc and GND on the IC breakout board I used and increase the SPI programming speed. Lowering speeds actually increased errors! I found a nice behavior at 10kHz SPI reading and writing. I tested this by reading multiple times from the IC and comparing md5sums between reads. Must consistently read fine! Then I did a complete erase before doing the final write. And then after writing another reading and comparing to the original file. But unfortunately I discover this problem after I had programmed the IC once. I only had a backup from when I still had data corruption during reading. Fortunately, this backup binary was not corrupted enought to case a Checksum error on the first NVRAM space. (this I guessed later) - During my searchs and in this case with the assistance of AI search assist I was able to get to some ideas of how to calculate the CRC. AI made a lot of wrong assumptions, hallucinated a lot of times, incorrectly extrapolate a lot. It gave different answers for almost the same questions in different days. Until it finally helped me find the correct answer together with my own hex editing examination tools, the three different CFE files I had and the different behaviors I was getting.

This was the final solution:

  1. Using a raspberry pi zero w as an SPI IC flasher: do a backup of the original SPI. Important for getting the MAC addresses and for corroborating that the CRC calculation was correct. This wasn't perfect: the reading of this backup was possibly corrupted.
  2. Use the donor CFE binary but: - Adjust all the MAC addresses using the original backup from my SPI. - Adjust the pin or secret according to the label on the product - Check that all the wireless power configurations and other calibration details were correct. I didn't need to adjust any. - Recalculate the checksum field. This was an special CRC8 checksum using polinomial 0x9B LSB-reflected to 0xAB with inverted shifting. I had a lot of problems to get the right calculation.

The CRC problem

Detailed information of the Buffalo WZR-D1800h for unbricking and hacking

Real UART Pin-out (checked!):

  1. Vcc (checked)
  2. GND (checked)
  3. TX (output from the device) (checked)
  4. RX (send signals here) (checked)

The device has an empty pair or tiny pads near the RX pin. One pad connects to RX and the other to Vcc. One could put a pull-up resistor there. I did and it didn't change anything. I later removed it. Now that the device is unbricked, TX and RX work without anything on these pads. Don't solder anything: it is not necessary!

Shorting NAND or SPI IC:

Pressing AOSS during booting:

JTAG

CFE binary layout

0x000000 -> 0x0003FF: CFE initialization code (very important to be not corrupted)
0x000400 -> 0x000A07: NVRAM_1: First factory NVRAM space (mostly sure)
0x050000 -> 0x0570E7: NVRAM_2: First main NVRAM space (guess)
0x070000 -> 0x077FFF: NVRAM_3: Second factory NVRAM space (guess)
0x078000 -> 0x078687: NVRAM_4: Second main NVRAM space (guess)

one NVRAM layout

0x0000 32bits: MAGIC Key: FLSH
0x0004 32bits: Length: length of whole NVRAM block
0x0005 1byte: Checksum (calculated from 0x0006 till the section end)
0x0006 1byte: version: 0x01
0x0007 2bytes: Flags: 0x0000
0x0008 -> end of section: Data
Data: key=value ending with \00
Data section ends with \00\00
CFE> show devices
Device Name          Description
-------------------  ---------------------------------------------------------
uart0                NS16550 UART at 0x18000300
uart1                NS16550 UART at 0x18000400
flash0               ST Serial flash size 512KB
flash0.boot          ST Serial flash offset 00000000 size 256KB
flash0.trx           ST Serial flash offset 00040000 size 1KB
flash0.os            ST Serial flash offset 0004001C size 224KB
flash0.nvram         ST Serial flash offset 00078000 size 32KB
flash1.boot          ST Serial flash offset 00000000 size 256KB
flash1.trx           ST Serial flash offset 00040000 size 224KB
flash1.nvram         ST Serial flash offset 00078000 size 32KB
nflash0.trx          Samsung NAND flash offset 00000000 size 1KB
nflash0.os           Samsung NAND flash offset 0000001C size 131072KB
nflash1.trx          Samsung NAND flash offset 00000000 size 121856KB
nflash1.brcmnand     Samsung NAND flash offset 07700000 size 9216KB
eth0                 Broadcom BCM47XX 10/100/1000 Mbps Ethernet Controller
*** command status = 0
CFE> show clocks
Current clocks: 600/300/150/25 Mhz.


CFE> show pci
PCI bus 0 slot 0/0: vendor 0x14e4 product 0x0800 (flash memory, rev 0x01)
PCI bus 0 slot 1/0: vendor 0x14e4 product 0x4715 (ethernet network, rev 0x01)
PCI bus 0 slot 4/0: vendor 0x14e4 product 0x471a (USB serial bus, interface 0x10, rev 0x0)
PCI bus 0 slot 4/1: vendor 0x14e4 product 0x471a (USB serial bus, interface 0x20, rev 0x0)
PCI bus 0 slot 5/0: vendor 0x14e4 product 0x0820 (PCI bridge, rev 0x01)
PCI bus 0 slot 6/0: vendor 0x14e4 product 0x0820 (PCI bridge, rev 0x01)
PCI bus 0 slot 7/0: vendor 0x14e4 product 0x052e (undefined subclass 0xff, interface 0xff)
PCI bus 0 slot 8/0: vendor 0x14e4 product 0x080e (RAM memory, rev 0x01)
PCI bus 0 slot 9/0: vendor 0x14e4 product 0x0534 (undefined subclass 0xff, interface 0xff)
*** command status = 0

CFE> show memory
Range Start  Range End    Range Size     Description
------------ ------------ -------------- --------------------
000000000000-000006FFFFFF (000007000000) DRAM (available)
000007165000-000007FFFFFF (000000E9B000) DRAM (available)

CFE> nvram getall
DEF-p_wireless_eth1_11a-crypto=aes
DEF-p_wireless_eth2_11bg-crypto=aes
boardrev=0x1204
et0macaddr=10-6F-3F-16-17-76
4331_cckbw20ul2gpo=0x3333
boot_wait=off
watchdog=3000
et0mdcport=0
43a2_mcsbw805glpo=0x00000000
hw_rev=0
reset_gpio=5
pmon_ver=CFE 6.30.15-1.04
vlan2ports=0 8
43a2_mcsbw805ghpo=0x11111111
gpio4=robo_reset
sromrev=8
boardtype=0xf52e
43a2_mcsbw405glpo=0x00000000
4331_cckbw202gpo=0x3333
lan_netmask=255.255.255.0
43a2_mcsbw405ghpo=0x33333333
nvram_version=1.00
region=US
vlan2hwname=et0
pmon_date=Tue Apr 24 09:04:01 JST 2012
DEF-p_wireless_eth1_11a-authmode=psk
xtalfreq=25000
boardflags2=0x0
DEF-p_wireless_eth1_11a-wpapsk=u3h5nykr5a4nj
wait_time=3
DEF-p_wireless_eth2_11bg-wpapsk=u3h5nykr5a4nj
melco_id=RD_BB11119
wl_dmatxctl=0x24c0040
43a2_maxp5ga0=40,100,100,66
43a2_maxp5ga1=40,100,100,66
43a2_maxp5ga2=40,100,100,66
wl_dmarxctl=0x24c0000
4331_mcsbw20ul2gpo=0x11111111
clkfreq=600,300,150
lan_ipaddr=192.168.11.1
vlan1hwname=et0
DEF-p_wireless_eth2_11bg-authmode=psk
sdram_config=0x0105
vlan1ports=1 2 3 4 8*
boardflags=0x110
wandevs=vlan2
DEF-p_wireless_eth1_11a-authmode_ex=wpa2-psk
sdram_refresh=0x0000
sdram_ncdl=0x00000000
4331_mcs32po=0x0002
pincode=62456838
product=WZR-D1800H
DEF-p_wireless_eth2_11bg-authmode_ex=wpa2-psk
43a2_mcsbw205glpo=0x00000000
et0phyaddr=30
wl_pcie_mrrs=128
landevs=vlan1 wl0 wl1
4331_maxp2ga0=52
4331_maxp2ga1=52
4331_maxp2ga2=52
43a2_mcsbw205ghpo=0x00000000
4331_legofdmbw20ul2gpo=0x11111111
43a2_mcsbw1605glpo=0x00000000
sdram_init=0x0000
43a2_mcsbw1605ghpo=0x00000000
4331_legofdmbw202gpo=0x11111111
4331_mcsbw402gpo=0x88888888
custom_id=0
boardnum=00
4331_mcsbw202gpo=0x11111111
bootflags=1
size: 1668 bytes (31100 left)

NAND details:

No idea. I didn't have to get to this

Resources

References

https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324862

Real hndcrc8 table: https://github.com/spotify/linux/blob/master/drivers/staging/brcm80211/util/bcmutils.c#L570 https://git.wut.ee/qi-hardware/openwrt-xburst/src/commit/843274aa37f00bacea2b88c03525c8d6564a54c7/package/nvram/src/crc.c https://github.com/GetOcean/ocean-os-drivers/blob/45785ee9d212973039d1e993043873bc81922106/ap6210.drivers/bcmutils.c#L1369 https://github.com/Coool/Broadcom-CFE/blob/cb59f58fdfdd849430cb59258f960b4da7ebef69/cfe/main/bcmnvram.c#L231

HndCRC8 used: https://git.wut.ee/qi-hardware/openwrt-xburst/src/commit/843274aa37f00bacea2b88c03525c8d6564a54c7/package/nvram/src/nvram.c

NVRAMCRCSTART_POSITION: https://git.wut.ee/qi-hardware/openwrt-xburst/src/commit/843274aa37f00bacea2b88c03525c8d6564a54c7/package/nvram/src/nvram.h

General Info: https://deviwiki.com/wiki/Buffalo_WZR-D1800H https://wiki.dd-wrt.com/wiki/Buffalo_WZR-D1800H

dd-wrt downloads:

https://github.com/Coool/Broadcom-CFE/blob/cb59f58fdfdd849430cb59258f960b4da7ebef69/cfe/main/bcmnvram.c#L231

dd-wrt recommended downloads (according to webpage): Danger!!! Warning!!!. This was probably the reason I bricked my device. The webupgrade points to a bin file, and the factory flash points to a trx. It is the other way around! https://dd-wrt.com/support/router-database/?model=WZR-D1800H%20(AC1750)_-