Baofeng-UV-5RM-5RH-RE icon indicating copy to clipboard operation
Baofeng-UV-5RM-5RH-RE copied to clipboard

Info: other compatible firmwares with tools

Open OK2MOP opened this issue 11 months ago • 37 comments

Hello, as the E-mail address in commits is probably not working and I was not able to contact repo owner directly, I attach here just a small update for potential additional reverse engineering:

  1. the decryption/encryption tools work also for Radtel .kdhT and .kdhX firmware files (RT-470, RT-490) and potentially other firmware updates I was not able to get (e.g. JJCC8629 is a possible candidate)
  • .kdhT is equivalent to the .BF file with two-part firmware file (with second FW part which includes code in the original SYSTEM bootloader area)
  • .kdhX is just a single encrypted firmware (decryptable with decrypt binary) in main code memory
  1. Some radios (like UV-17/18/21 Pro use different LPQFP48 CPU with 128kB flash and 32kB RAM. As I do not have access to the firmware besides RT-490 (with two different versions of FW 1.03, for old V1 radio and newer V2 radio), I can only guess which:
  • for old V1 RT-490 the CPU is unknown (around 86-88 records in vector table - I was not able to match it to any Artery AT32 CPUs)
  • for newer (end of 2022+) V2, the CPU it is probably an AT32F415CCT7 clone (but one of the last reserved vectors is set to default handler instead of 0 so it is not a perfect match)
  • if anybody can share Baofeng UV18PRO or UV17PRO firmware, I would like to look at it

73, Pavel, OK2MOP

OK2MOP avatar Mar 10 '24 10:03 OK2MOP