diff --git a/_ont/ont-comtrend-grg-4284.md b/_ont/ont-comtrend-grg-4284.md
index 3d6579e8..36b7e4a4 100644
--- a/_ont/ont-comtrend-grg-4284.md
+++ b/_ont/ont-comtrend-grg-4284.md
@@ -70,7 +70,7 @@ Simple change with a hex editor can be done to enable full shell, inside /lib/li
Then add /bin/ash to /etc/shells to enable normal shell.
-Binary patch is required to prevent `/bin/startup` from reseting ME 256 and 257 parameters on reboot.
+In case device contains locked default configuration `/etc/config_default.xml` can be modified to undo any unwanted restrictions.
## Flashing new firmware
diff --git a/_ont/ont-nokia-g-010s-q.md b/_ont/ont-nokia-g-010s-q.md
index 9e769683..ffab5672 100644
--- a/_ont/ont-nokia-g-010s-q.md
+++ b/_ont/ont-nokia-g-010s-q.md
@@ -16,7 +16,7 @@ alias: CIG G-97S
| ODM Product Code | G-97S |
| Chipset | RTL9601CI |
| Flash | 16 MB (Macronix MX25L12835F) |
-| RAM | |
+| RAM | 32 MB |
| System | |
| HSGMII | |
| Optics | |
@@ -33,10 +33,17 @@ alias: CIG G-97S
{% include_relative ont-nokia-useful-command.md %}
+## Enable full telnet shell
+Full telnet and secondary factory IP can be enabled by sending [Nokia magic packet](https://github.com/YuukiJapanTech/CA8271x/blob/main/doc/rootShell.md#nokia-xs-010x-r).
+
+If factory mode is enabled sucessfully second IP `192.168.188.1/24` will be assinged to SFP LAN interface.
+
+Newly available login credentials will be `ATE` / `CATS2388` and `ONTUSER` / `sha256 of SN formated as GPONa1b2c3d4` with GponCLI shell.
+
# Miscellaneous Links
- [Nokia G-010S-Q](https://github.com/Anime4000/RTL960x/issues/52)
-- [CUG G-97S DataSheet](https://www.cigtech.com/wp-content/uploads/2018/09/G-97S_DataSheet_V2.pdf)
+- [CIG G-97S DataSheet](https://web.archive.org/web/20230803034001/https://www.cigtech.com/wp-content/uploads/2018/09/G-97S_DataSheet_V2.pdf)
- [MIB file parser](https://github.com/nanomad/nokia-ont-mib-parser) for NOKIA's GPON ONTs (*helps you parsing the .mib file located in `/mnt/rwdir`*)
diff --git a/_ont/ont-sercomm-fg1000r.md b/_ont/ont-sercomm-fg1000r.md
index 96420466..784c67d4 100644
--- a/_ont/ont-sercomm-fg1000r.md
+++ b/_ont/ont-sercomm-fg1000r.md
@@ -7,29 +7,29 @@ parent: Sercomm
# Hardware Specifications
-| | |
-| --------------- | ----------------------- |
-| Vendor/Brand | Sercomm |
-| Model | FG1000R |
-| ODM | ✅ |
-| Chipset | RTL9602C |
-| Flash | 128MB (MXIC MX35LF1GE4AB) |
-| RAM | 64MB |
-| CPU | |
-| CPU Clock | 625 MHz |
-| Bootloader | U-Boot RSDK 2011.12.NA-svn5 |
-| Load addr | |
-| 2.5GBaseT | ✅ |
-| PHY Ethernet | Realtek RTL8221B |
-| Optics | LC/APC |
-| IP address | 192.168.1.1/24 |
+| | |
+| --------------- | ------------------------------ |
+| Vendor/Brand | Sercomm |
+| Model | FG1000R |
+| ODM | ✅ |
+| Chipset | RTL9602C |
+| Flash | 128MB (MXIC MX35LF1GE4AB) |
+| RAM | 64MB |
+| CPU | |
+| CPU Clock | 625 MHz |
+| Bootloader | U-Boot RSDK 2011.12.NA-svn5 |
+| Load addr | |
+| 2.5GBaseT | ✅ |
+| PHY Ethernet | Realtek RTL8221B |
+| Optics | LC/APC |
+| IP address | 192.168.1.1/24 |
| Web Gui | ✅, User: Tech Password: ftth@! |
-| SSH | |
-| Telnet | |
-| Serial | ✅, only TX |
-| Serial baud | 115200 |
-| Serial encoding | 8-N-1 |
-| Form Factor | ONT |
+| SSH | |
+| Telnet | |
+| Serial | ✅, only TX |
+| Serial baud | 115200 |
+| Serial encoding | 8-N-1 |
+| Form Factor | ONT |
{% include image.html file="fg1000r_rear.jpg" alt="Sercomm FG1000R" caption="Sercomm FG1000R rear" %}
diff --git a/_ont/ont-sercomm-fgs202.md b/_ont/ont-sercomm-fgs202.md
index f976c72f..54267ca7 100644
--- a/_ont/ont-sercomm-fgs202.md
+++ b/_ont/ont-sercomm-fgs202.md
@@ -159,9 +159,10 @@ FGS202:/# show i2c (ASCII view added for readability)
000001d0: 3230 3231 3132 0000 5343 4f4d 4647 5332 202112..SCOMFGS2
000001e0: 3032 3131 3200 ff00 0000 1000 0000 0000 02112...........
000001f0: 0000 0000 0000 0000 0000 0000 0000 0020 ...............
+```
It can also be read and written using an external I2C reader.
-```
+
# Advanced settings
@@ -181,14 +182,18 @@ Simple U-Boot-style storage `key=value\0` padded by 0xFF, after modification, a
```py
from zlib import crc32
-wholeflash = open("FGS202.bin", "rb").read() # Full SPI dump
-ubootenv = wholeflash[262144:262144+65536] # 0x40000-0x5FFFF
-factoryenv = wholeflash[327680:327680+65536] # 0x50000-0x6FFFF
-ecosenv = wholeflash[393216:393216+65536] # 0x60000-0x7FFFF
+wholeflash = open("FGS202.bin", "rb").read() # Full SPI dump
+ubootenv = wholeflash[262144:262144+65536] # 0x40000-0x50000
+factoryenv = wholeflash[327680:327680+65536] # 0x50000-0x60000
+ecosenv = wholeflash[393216:393216+65536] # 0x60000-0x70000
+ubootenv2 = wholeflash[262144:262144+65536] # 0x80000-0x90000
+ecosenv2 = wholeflash[8323072:8323072+65536] # 0x7F0000-0x800000
print(f'U-Boot\n| CRC: {ubootenv[0:4].hex()} | Version {ubootenv[4:5]} | New CRC: {crc32(ubootenv[5:]):08x} ')
print(f'Factory\n| CRC: {factoryenv[0:4].hex()} | Version {factoryenv[4:5]} | New CRC: {crc32(factoryenv[5:]):08x} ')
print(f'eCos\n| CRC: {ecosenv[0:4].hex()} | Version {ecosenv[4:5]} | New CRC: {crc32(ecosenv[5:]):08x} ')
+print(f'U-Boot backup\n| CRC: {ubootenv2[0:4].hex()} | Version {ubootenv2[4:5]} | New CRC: {crc32(ubootenv2[5:]):08x}')
+print(f'eCos backup\n| CRC: {ecosenv2[0:4].hex()} | Version {ecosenv2[4:5]} | New CRC: {crc32(ecosenv2[5:]):08x}')
```
## Decrypting "encrypt_data" variable from flash
@@ -221,10 +226,14 @@ At boot time, this variable is read by the modified U-Boot and waits for [sercom
Due to an uninitialized SFP EEPROM, a simple SFP-to-Ethernet converter is required.
-The input for sercomm-recovery tool must be a complete dump of complete flash memory, the client writes only the Image0 and Image1 regions, and the rest is skipped (so a failed write will drop you back into recovery).
+The input for sercomm-recovery tool must be a complete dump of flash memory, the client writes only the Image0 and Image1 regions, and the rest is skipped (so a failed write will drop you back into recovery).
It is not possible to exit this mode until the write operation completes or the environment settings are manually reset to 0.
+## Boot and update log
+{% include serial_dump.html file="fgs202-boot.txt" alt="eCos boot" title="eCos boot" %}
+
+{% include serial_dump.html file="fgs202-flash.txt" alt="Update with sercomm-recovery" title="Update with sercomm-recovery" %}
# Hardware Modding
diff --git a/_ont/ont-tenda-hg1-patch.md b/_ont/ont-tenda-hg1-patch.md
new file mode 100644
index 00000000..88675364
--- /dev/null
+++ b/_ont/ont-tenda-hg1-patch.md
@@ -0,0 +1,143 @@
+---
+title: OMCI reset patch
+has_children: false
+layout: default
+parent: Tenda HG1
+---
+
+## Premade patch for V1.0.2
+This patch is for /bin/startup with MD5 `5e6db6934d662b5cef2f4c74b8cdf639`
+
+```diff
+1073c1073
+< 00004300: 0040 2821 8f82 81c0 0040 c821 0000 0000 .@(!.....@.!....
+---
+> 00004300: 0040 2821 8f82 81c0 0040 c821 0320 f809 .@(!.....@.!. ..
+1205c1205
+< 00004b40: 0000 0000 0000 0000 8fdc 0010 27c2 0030 ............'..0
+---
+> 00004b40: 0320 f809 0000 0000 8fdc 0010 27c2 0030 . ..........'..0
+1207c1207
+< 00004b60: 0000 0000 0000 0000 8fdc 0010 2404 0008 ............$...
+---
+> 00004b60: 0320 f809 0000 0000 8fdc 0010 2404 0008 . ..........$...
+1256c1256
+< 00004e70: 0040 c821 0000 0000 0000 0000 8fdc 0010 .@.!............
+---
+> 00004e70: 0040 c821 0320 f809 0000 0000 8fdc 0010 .@.!. ..........
+1258c1258
+< 00004e90: 0040 c821 0000 0000 0000 0000 8fdc 0010 .@.!............
+---
+> 00004e90: 0040 c821 0320 f809 0000 0000 8fdc 0010 .@.!. ..........
+1262c1262
+< 00004ed0: 0040 2821 8f82 81c0 0040 c821 0000 0000 .@(!.....@.!....
+---
+> 00004ed0: 0040 2821 8f82 81c0 0040 c821 0320 f809 .@(!.....@.!. ..
+1264c1264
+< 00004ef0: 0040 2821 8f82 81c0 0040 c821 0000 0000 .@(!.....@.!....
+---
+> 00004ef0: 0040 2821 8f82 81c0 0040 c821 0320 f809 .@(!.....@.!. ..
+```
+
+Resulting patched file should have MD5 of `99aaaece6b7ed5a9ee0a075443d98943`
+
+Add the following to `/etc/version.sh`, `rootfs_extracted/etc/scripts/chk_swver_2.sh` and `rootfs_extracted/etc/scripts/chk_swver.sh` to skip script checks by creating empty file inside JFFS2 config.
+
+```diff
+> if [ -f /var/config/skip_version ]; then
+> echo "Version adaptation bypass"
+> exit 0
+> fi
+```
+
+## Tweaked default configuration
+
+Enable telnet on LAN, disable http and telnet on WAN.
+
+SSH and FTP components are removed from firmware and can't be enabled.
+
+```diff
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+<
+---
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+>
+```
+
+
diff --git a/_ont/ont-tenda-hg1.md b/_ont/ont-tenda-hg1.md
index d6a87fbd..3e17b7af 100644
--- a/_ont/ont-tenda-hg1.md
+++ b/_ont/ont-tenda-hg1.md
@@ -1,6 +1,6 @@
---
title: Tenda HG1
-has_children: false
+has_children: true
layout: default
parent: Tenda
---
@@ -39,7 +39,7 @@ parent: Tenda
## List of software versions
-- V1.7.1
+- V1.0.2
# List of partitions
@@ -80,6 +80,14 @@ Device has a hidden page `http://192.168.1.1/tddeviceinfo.asp` for configuring O
OMCI equipment ID (ME 257) and OMCI hardware version (ME 256) are hardcoded into `/etc/version.sh` and `/bin/startup` requiring a firmware patch to change.
+## WAN backdoor account
+There are hardcoded credentials for WAN user, it's recommended WWW and Telnet are disabled on and this second password changed.
+
+```xml
+
+
+```
+
# Miscellaneous Links
- [Hacking RTL960x](https://github.com/Anime4000/RTL960x)
diff --git a/_ont/ont-zyxel-pmg5100-t0.md b/_ont/ont-zyxel-pmg5100-t0.md
index b453d990..446eb50f 100644
--- a/_ont/ont-zyxel-pmg5100-t0.md
+++ b/_ont/ont-zyxel-pmg5100-t0.md
@@ -30,3 +30,32 @@ parent: Zyxel
{% include image.html file="zyxel-pmg5100\port.jpg" alt="PM5100-T0" caption="PM5100-T0" %}
{% include image.html file="zyxel-pmg5100\back-board.jpg" alt="PM5100-T0 Teardown" caption="PM5100-T0 Teardown" %}
{% include image.html file="zyxel-pmg5100\front-board.jpg" alt="PM5100-T0 Teardown" caption="PM5100-T0 Teardown" %}
+
+## List of software versions
+- V5.42-ACEQ-0b10 (Cetin)
+- V5.42-ACBF.1.1-C0 (Zyxel)
+
+## Unlock bootloader and root shell
+Full linux shell can be accessed if the current firmware allows it, this ONT has per-device password burned into flash.
+
+Depending on Z-Loader version bootloader access might be protected with supervisors password until `EngDebugFlag` is enabled.
+
+Default passwords can be obtained with normal ATEN/ATSE unlock process.
+
+```sh
+# Generate unlock seed
+ATSE PM5100-T0
+# Generate ATEN key with https://github.com/cjdelisle/ATENv3
+ATEN 1,RESULT
+# Allow nvram write
+ATBT 1
+# Write EngDebugFlag to nvram
+ATSB
+# Dump passwords from nvram
+ATCK
+```
+
+If network upgrade isn't disabled by ISP branding [zyeng](https://github.com/bmork/zyxel-hacks) tool can be used to write EngDebugFlag it over the network.
+
+When both methods fail only option is to desolder the SPI flash and locate passwords inside U-Boot ENV.
+
diff --git a/_ont/serial_dump/fgs202-boot.txt b/_ont/serial_dump/fgs202-boot.txt
new file mode 100644
index 00000000..93da8fdb
--- /dev/null
+++ b/_ont/serial_dump/fgs202-boot.txt
@@ -0,0 +1,66 @@
+ROM: V1.1.4
+ROM: CFG 0x00000006
+ROM: SFLASH-4
+hw fuse format 1
+
+
+U-Boot 2011.12-lantiq-gpon-1.2.20.1-svn20 (Aug 10 2015 - 13:49:58), Build: falcon_sfp
+
+Board: SFP
+DRAM: internal: 1 MiB
+Now running in RAM - U-Boot at: 9f2c4000
+SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB
+Chip: FALCON-SR (A22)
+Bootmode: 0x06
+Reset cause: Power-On Reset
+CPU Clock: 400 MHz
+Done!
+Net: SGMII, SERDES [PRIME]
+
+Type run flash_nfs to mount root filesystem over NFS
+
+SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB
+SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB
+SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB
+active_img 0, committed_img 1
+pid_addr 0x2a0ce8
+dbSign Addr: 0x9f200208
+imgNum: 1
+img 0: start addr: 0x100000, length: 0x1a0ce8
+checksum: 0xa39a73eb
+crc32 result: 0xa39a73eb
+check sum OK
+name c_img
+value 1
+name activate_image
+value 0
+Erasing SPI flash...Writing to SPI flash...done
+SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB
+
+***************************************************
+ Sercomm Boot Version 2.0.2.0
+
+***************************************************
+No sc dl flag.
+gpio_id:8 no found
+Entering Firmware : Everything is OK.
+No sc dl flag.
+## Starting application at 0x10000000 ...
+Overall used memory: 150616
+Available packet buffer: 769984 (llt min 6401, llt max 18432)
+Init flash support
+M25PXX : Init device 'Macronix 64 Mbit' with JEDEC ID 0xC22017/0x0000.
+Found flash at 0x00000000-0x007fffff
+Flash bank with 128 sectors, sector size is 65536 bytes
+Find valid uboot environment in env_off and env_end_off
+Machine: Falcon SFP Stick (SFP)
+Set image#0 version: SCOMFGS202112
+Set image#1 version: SCOMFGS202112
+Successfully stored environment to 0x7f0000
+Successfully stored environment to 0x60000
+Image start address: 0xb0100000
+Image 0: 0xB0100000 - valid
+Image 1: 0xB0480000 - valid
+ONT Boot up #1 image
+FALC(tm) ON Optic Driver, version 7.4.0.0 (c) Copyright 2015, Lantiq Beteiligungs-GmbH & Co. KG
+FALC(tm) ON Base Driver, Version 7.3.3.0 (c) Copyright 2015, Lantiq Beteiligungs-GmbH & Co. KG
diff --git a/_ont/serial_dump/fgs202-flash.txt b/_ont/serial_dump/fgs202-flash.txt
new file mode 100644
index 00000000..5b3b3fa3
--- /dev/null
+++ b/_ont/serial_dump/fgs202-flash.txt
@@ -0,0 +1,82 @@
+ROM: V1.1.4
+ROM: CFG 0x00000006
+ROM: SFLASH-4
+hw fuse format 1
+
+
+U-Boot 2011.12-lantiq-gpon-1.2.20.1-svn20 (Aug 10 2015 - 13:49:58), Build: falcon_sfp
+
+Board: SFP
+DRAM: internal: 1 MiB
+Now running in RAM - U-Boot at: 9f2c4000
+SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB
+Chip: FALCON-SR (A22)
+Bootmode: 0x06
+Reset cause: Power-On Reset
+CPU Clock: 400 MHz
+Done!
+Net: SGMII, SERDES [PRIME]
+
+Type run flash_nfs to mount root filesystem over NFS
+
+SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB
+SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB
+SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB
+active_img 0, committed_img 1
+pid_addr 0x2a1a48
+dbSign Addr: 0x9f200208
+imgNum: 1
+img 0: start addr: 0x100000, length: 0x1a1a48
+checksum: 0x1124fafc
+crc32 result: 0x1124fafc
+check sum OK
+name c_img
+value 1
+name activate_image
+value 0
+Erasing SPI flash...Writing to SPI flash...done
+SF: Detected MX25L6405D with page size 64 KiB, total 8 MiB
+
+***************************************************
+ Sercomm Boot Version 2.0.2.0
+
+***************************************************
+get sc dl flag.
+DEBUG_INF:===================================================
+DEBUG_INF:Sercomm Upgrade(Module Ver 2.14.02.24) Start!
+DEBUG_INF:===================================================
+
+0x0000: 00 c0 02 12 35 79
+Error: SGMII TBI not in sync!
+Error: SGMII TBI not in sync!
+SERDES: Link Speed is 1000 Mbps - FULL duplex connection
+DEBUG_INF:ecc bytes 0
+PCBASN = R.BNN72O048E
+DEBUG_INF:normal upgrade.
+DEBUG_INF:Erase Done.
+DEBUG_INF:Program Starting.
+DEBUG_INF:Verify Starting.
+DEBUG_INF:===================================================
+DEBUG_INF:= Stats of this Sercomm Upgrade is as below: =
+DEBUG_INF:===================================================
+DEBUG_INF:Following Partitions NOT Erased,
+DEBUG_INF: Index Name Offset Length
+DEBUG_INF: 0 u-boot 0 40000
+DEBUG_INF: 1 u-boot-env 40000 10000
+DEBUG_INF: 2 factory_data 50000 10000
+DEBUG_INF: 3 fw_config 60000 10000
+DEBUG_INF: 4 sercomm_log 70000 10000
+DEBUG_INF: 5 u-boot-env-second 80000 10000
+DEBUG_INF: 10 image1_reserve 7f0000 10000
+DEBUG_INF:---------------------------------------------------
+DEBUG_INF:Following Partitions Updated,
+DEBUG_INF: Index Name Bad Cnt Dropped
+DEBUG_INF: 6, reserved_area 0 0
+DEBUG_INF: 7, image0 0 0
+DEBUG_INF: 8, image0_reserve 0 0
+DEBUG_INF: 9, image1 0 0
+DEBUG_INF:===================================================
+name sc_dl
+value ff
+Erasing SPI flash...Writing to SPI flash...done
+
diff --git a/_ont_xgs/ont-comtrend-grg-4362-patch.md b/_ont_xgs/ont-comtrend-grg-4362-patch.md
new file mode 100644
index 00000000..65b8dd58
--- /dev/null
+++ b/_ont_xgs/ont-comtrend-grg-4362-patch.md
@@ -0,0 +1,34 @@
+---
+title: OMCI unlock patch
+has_children: false
+layout: default
+parent: Comtrend GRG-4362
+---
+
+## Premade patch for CTN-1.0.8b16
+This patch is for /bin/startup from firmware CTN-1.0.8b16 with MD5 `a5d76a686ebb6683e25d2e11d004a707`
+
+```diff
+< 00005a30: 1f00 0071 8002 0054 0000 00b0 0120 3b91 ...q...T..... ;.
+< 00005a40: e0fa 8052 1bf4 ff97 0000 00b0 0120 3b91 ...R......... ;.
+< 00005a50: 00fb 8052 17f4 ff97 0000 00b0 0120 3b91 ...R......... ;.
+< 00005a60: 80fb 8052 13f4 ff97 0000 00b0 0120 3b91 ...R......... ;.
+< 00005a70: e0fb 8052 0ff4 ff97 0100 8052 4000 8052 ...R.......R@..R
+< 00005a80: b0f4 ff97 02fd ff97 1f00 0071 cb17 0054 ...........q...T
+---
+> 00005a30: 1f00 0071 8002 0054 1f20 03d5 1f20 03d5 ...q...T. ... ..
+> 00005a40: 1f20 03d5 1f20 03d5 1f20 03d5 1f20 03d5 . ... ... ... ..
+> 00005a50: 1f20 03d5 1f20 03d5 1f20 03d5 1f20 03d5 . ... ... ... ..
+> 00005a60: 1f20 03d5 1f20 03d5 1f20 03d5 1f20 03d5 . ... ... ... ..
+> 00005a70: 1f20 03d5 1f20 03d5 1f20 03d5 1f20 03d5 . ... ... ... ..
+> 00005a80: 1f20 03d5 02fd ff97 1f00 0071 cb17 0054 . .........q...T
+```
+
+Resulting patched file should have MD5 of `e58fb01c2952e2dc053e8fa8638e45f7`
+
+## Mannual patch for other versions
+
+To patch other versions of startup, locate function that prints "startELan fail, plz check!" and delete the calls to mib_set with NOPs (0xd503201f)
+
+{% include image.html file="grg-4362/mib_patch.jpg" alt="Patch ASM" caption="Patch ASM" %}
+
diff --git a/_ont_xgs/ont-comtrend-grg-4362.md b/_ont_xgs/ont-comtrend-grg-4362.md
index e550f8da..e7eb979b 100644
--- a/_ont_xgs/ont-comtrend-grg-4362.md
+++ b/_ont_xgs/ont-comtrend-grg-4362.md
@@ -1,6 +1,6 @@
---
title: Comtrend GRG-4362
-has_children: false
+has_children: true
layout: default
parent: Comtrend
---
@@ -20,7 +20,7 @@ parent: Comtrend
| PHY Ethernet | RTL8261B |
| Optics | SC/APC (SEMTECH GN28L96) |
| IP address | 192.168.1.1/24 |
-| Web Gui | ✅ user `root`, password `root` |
+| Web Gui | ✅ |
| SSH | ✅ |
| Telnet | ✅ |
| FTP | ✅, Download only |
@@ -31,9 +31,9 @@ parent: Comtrend
# External/Internal Photo
-{% include image.html file="comtrend_grg-4362_teardown_1.jpg" alt="Comtrend GRG-4362 Top Cover" caption="Comtrend GRG-4362 Top Cover" %}
-{% include image.html file="comtrend_grg-4362_teardown_2.jpg" alt="Comtrend GRG-4362 Bottom Cover" caption="Comtrend GRG-4362 Bottom Cover" %}
-{% include image.html file="comtrend_grg-4362_teardown_3.jpg" alt="Comtrend GRG-4362 PCB" caption="Comtrend GRG-4362 PCB" %}
+{% include image.html file="grg-4362/comtrend_grg-4362_teardown_1.jpg" alt="Comtrend GRG-4362 Top Cover" caption="Comtrend GRG-4362 Top Cover" %}
+{% include image.html file="grg-4362/comtrend_grg-4362_teardown_2.jpg" alt="Comtrend GRG-4362 Bottom Cover" caption="Comtrend GRG-4362 Bottom Cover" %}
+{% include image.html file="grg-4362/comtrend_grg-4362_teardown_3.jpg" alt="Comtrend GRG-4362 PCB" caption="Comtrend GRG-4362 PCB" %}
## Hardware Revisions
@@ -303,11 +303,12 @@ mkdir /var/tmp
mkdir /var/config
mount -t ubifs ubi0:ubi_Config /var/config/
-# Read device login
+# To regain access from locked ISP firmware:
+# 1. Read device login
flash get SUSER_NAME
flash get SUSER_PASSWORD
-# Unblock ACL rules
+# 2. Unblock ACL rules
flash set ACL_IP_TBL.0.any 0
flash set ACL_IP_TBL.0.telnet 1
flash set ACL_IP_TBL.0.web 1
@@ -321,7 +322,7 @@ flash set ACL_IP_TBL.1.https 0
flash set ACL_IP_TBL.1.ssh 0
flash set ACL_IP_TBL.1.icmp 0
-# Enable full shell instead of CLI
+# 3. Enable full shell instead of CLI
# This script runs too early in boot process, delay was needed to get /var into right state
cat < /var/config/run_customized_sdk.sh
#!/bin/sh
@@ -345,8 +346,9 @@ Simple change with a hex editor can be done to enable full shell, inside /lib/li
Then add /bin/ash to /etc/shells to enable normal shell.
-Binary patch is required to prevent `/bin/startup` from reseting ME 256 and 257 parameters on reboot.
+In case device contains locked default configuration `/etc/config_default.xml` can be modified to undo any unwanted restrictions.
+Binary patch is required to prevent `/bin/startup` from reseting ME 256 and 257 parameters on reboot.
## Flashing new firmware
- U-Boot
diff --git a/_ont_xgs/ont-kaon-pm1191-fwpatch.md b/_ont_xgs/ont-kaon-pm1191-fwpatch.md
new file mode 100644
index 00000000..80e3034c
--- /dev/null
+++ b/_ont_xgs/ont-kaon-pm1191-fwpatch.md
@@ -0,0 +1,66 @@
+---
+title: Extracting and repacking the rootfs
+has_children: false
+layout: default
+parent: KAON PM1191
+---
+
+{% include alert.html content="Make sure you run all commands as root, otherwise you might get a damaged rootfs image" alert="Warning" icon="svg-warning" color="red" %}
+
+## Unpacking SquashFS from UBI volume
+
+```sh
+# ubireader_extract_images rootfs1.img
+# cp ubifs-root/X/squashfs_ubi/img-X_vol-squashfs_ubi.ubifs .
+# as root...
+unsquashfs -d rootfs_extracted/ img-X_vol-squashfs_ubi.ubifs
+```
+
+## Repacking SquashFS
+```sh
+rm -v new_squashfs.img
+mksquashfs rootfs_extracted/ new_squashfs.img -comp xz -b 131072 -always-use-fragments -no-recovery -noappend
+```
+
+## Repacking UBI volume
+
+Firstly create ubinize.cfg with volume settings:
+
+```ini
+[squashfs_ubi]
+mode=ubi
+image=new_squashfs.img
+vol_id=0
+vol_type=static
+vol_name=squashfs_ubi
+vol_alignment=1
+```
+
+Re-build volume:
+
+```sh
+rm -v new_rootfs1.ubi
+ubinize -o new_rootfs1.ubi -p 131072 -m 2048 -s 2048 ubinize.cfg
+```
+
+## Writing to flash
+
+Pay attention to what Image is active, inactive rootfs will be named `rootfs1` inside /proc/mtd.
+
+For safety only flash one slot at once to make recovery faster avoiding need for U-Boot Ymodem upload.
+
+# Documented modifications to rootfs
+
+## Enable WEB UI
+On builds not ending with `_eng` file `/sbin/httpd` was deleted to disable WEBUI, copying it from `_eng` build will restore its function.
+
+## Disable TR-069
+UCI configuration for TR-069 is saved inside `/etc/config/easycwmp`, deleteing ACS url will disable easycwmp process starting from its init script.
+
+## Installing full busybox
+Precompiled busybox binary with all its features can be found [here](https://github.com/YuukiJapanTech/CA8271x/tree/main/mod/busybox-full).
+
+Place the full version into /bin/busybox-full or overlayfs and only create symlinks for tools you need.
+
+Do not replace the old busybox binary, device uses mtd-utils version of ubi* commands and busybox implementation is incompatible if you replace them.
+
diff --git a/_ont_xgs/ont-kaon-pm1191.md b/_ont_xgs/ont-kaon-pm1191.md
index b421ee57..40860af6 100644
--- a/_ont_xgs/ont-kaon-pm1191.md
+++ b/_ont_xgs/ont-kaon-pm1191.md
@@ -1,6 +1,6 @@
---
title: KAON PM1191
-has_children: false
+has_children: true
layout: default
parent: KAON
---
diff --git a/_ont_xgs/ont-sercomm-rhg3006.md b/_ont_xgs/ont-sercomm-rhg3006.md
new file mode 100644
index 00000000..c1ecabc1
--- /dev/null
+++ b/_ont_xgs/ont-sercomm-rhg3006.md
@@ -0,0 +1,52 @@
+---
+title: Sercomm RHG3006
+has_children: false
+layout: default
+parent: Sercomm
+---
+
+# Hardware Specifications
+
+| | |
+| --------------- | -------------------------- |
+| Vendor/Brand | Sercomm |
+| Model | RHG3006 |
+| Chipset | Broadcom BCM68380 |
+| Flash | 4 Gbit (MXIC MX30LF4G28AD) |
+| RAM | 256 Mb |
+| Bootloader | Broadcom CFE |
+| 2.5GBaseT | ? |
+| Optics | SC/APC |
+| IP address | 192.168.1.1/24 |
+| POTS | 2x RJ11 |
+| WLAN 2.4Ghz | 802.11b/g/n/ax 4×4 MU-MIMO |
+| WLAN 5Ghz | 802.11a/ac/ax 4×4 MU-MIMO |
+| Web Gui | ✅ |
+| SSH | |
+| Telnet | |
+| Serial | ✅, only TX |
+| Serial baud | 115200 |
+| Serial encoding | 8-N-1 |
+| Form Factor | ONT HGU |
+
+
+{% include image.html file="rhg3006/rhg3006-pcb-top.jpg" alt="Sercomm RHG3006 top" caption="Sercomm RHG3006 top" %}
+{% include image.html file="rhg3006/rhg3006-pcb-back.jpg" alt="Sercomm RHG3006 back" caption="Sercomm RHG3006 back" %}
+{% include image.html file="rhg3006/rhg3006-wlan.jpg" alt="Sercomm RHG3006 WLAN" caption="Sercomm RHG3006 WLAN" %}
+
+## List of software versions
+- XF6_4.0.03.02 (Vodafone.cz)
+
+## OMCI Parameters
+| | |
+| ------------------------ | ------------- |
+| Main Software Version | XF6_4.0.03.02 |
+| Standby Software Version | XF6_4.0.03.02 |
+| Vendor ID | SCOM |
+| Version | RHG3006v2 |
+| GPON SN | SCOMa1b2c3d4 |
+| PLOAM Password | Unknown |
+| LOID | Unknown |
+| LOID Password | Unknown |
+| Equipment ID | RHG3006 |
+| OMCC Version | 161 (0xA1) |
diff --git a/_ont_xgs/ont-sercomm.md b/_ont_xgs/ont-sercomm.md
new file mode 100644
index 00000000..2e44445a
--- /dev/null
+++ b/_ont_xgs/ont-sercomm.md
@@ -0,0 +1,5 @@
+---
+title: Sercomm
+has_children: true
+layout: default
+---
\ No newline at end of file
diff --git a/assets/img/comtrend_grg-4362_teardown_1.jpg b/assets/img/grg-4362/comtrend_grg-4362_teardown_1.jpg
similarity index 100%
rename from assets/img/comtrend_grg-4362_teardown_1.jpg
rename to assets/img/grg-4362/comtrend_grg-4362_teardown_1.jpg
diff --git a/assets/img/comtrend_grg-4362_teardown_2.jpg b/assets/img/grg-4362/comtrend_grg-4362_teardown_2.jpg
similarity index 100%
rename from assets/img/comtrend_grg-4362_teardown_2.jpg
rename to assets/img/grg-4362/comtrend_grg-4362_teardown_2.jpg
diff --git a/assets/img/comtrend_grg-4362_teardown_3.jpg b/assets/img/grg-4362/comtrend_grg-4362_teardown_3.jpg
similarity index 100%
rename from assets/img/comtrend_grg-4362_teardown_3.jpg
rename to assets/img/grg-4362/comtrend_grg-4362_teardown_3.jpg
diff --git a/assets/img/grg-4362/mib_patch.jpg b/assets/img/grg-4362/mib_patch.jpg
new file mode 100644
index 00000000..c33e0933
Binary files /dev/null and b/assets/img/grg-4362/mib_patch.jpg differ
diff --git a/assets/img/rhg3006/rhg3006-pcb-back.jpg b/assets/img/rhg3006/rhg3006-pcb-back.jpg
new file mode 100644
index 00000000..02e3521f
Binary files /dev/null and b/assets/img/rhg3006/rhg3006-pcb-back.jpg differ
diff --git a/assets/img/rhg3006/rhg3006-pcb-top.jpg b/assets/img/rhg3006/rhg3006-pcb-top.jpg
new file mode 100644
index 00000000..b4966d39
Binary files /dev/null and b/assets/img/rhg3006/rhg3006-pcb-top.jpg differ
diff --git a/assets/img/rhg3006/rhg3006-wlan.jpg b/assets/img/rhg3006/rhg3006-wlan.jpg
new file mode 100644
index 00000000..b0593c6e
Binary files /dev/null and b/assets/img/rhg3006/rhg3006-wlan.jpg differ