Nội dung text DW5821e Research & Hacking
Dell DW5821e/Foxconn T77W968 References & Facts ● Made by FoxConn (SKU: T77W968) ○ Related products: ■ Telit LN940A9/LN940A11 (SKU: T77W676) ■ Telit 940 was used in Vaio machines. That’s why the Foxconn scripts mention vaio. ● IMEIs ○ The IMEIs all start with 35544609 -- if the next digits are 00, they are engineering samples. ● http://certid.org/document/3870460 ○ Explains labeling and serials, IMEI format ○ X02 has 00 imei prototype sample ○ A03 has 01-99 customer model ● LTE Hacks thread mentioning fastboot and other tools ● Whirlpool thread mentioning AT commands found in firmware (search for DIAG_ENABLE to find the post) ○ Also mentioned how to extract the file system from the firmware Unpacking the image is easy if anyone else wants to take a closer look: The actual image is found in 1.0.1.40_A08_02/DW5821e Snapdragon X20 LTE/Image/GC/T77W968.F1.0.0.4.2/. The sdx20-sysfs.ubi file contains three ubinized file systems which can be unpacked with e.g ubireader_extract_files from https://github.com/jrspruitt/ubi_reader after removing the first 12 bytes (All the files seem to have a 12 byte header which just needs to be skipped) ○ Mentions switching between “customers” (these are Foxconn customers). Customers include two variants of Dell and Vaio. Customers seem to influence the USB composition. ● FCC Test Report ○ Shows internals of modem under the head shield. ○ Main SOC: Qualcomm SDR845 ● Telit LN960 FCC Internal Pics ○ FCC pics show it as T77W698.11 ● Telit LN940 Linux User Guide ○ Section 6: Upgrade Firmware Image with Fastboot Method . ● https://github.com/fwupd/fwupd/issues/2200 ○ Details on fastboot flashing ● https://y1cj3stn5fbwhv73k0ipk1eg-wpengine.netdna-ssl.com/wp-content/uploads/2017/1 0/1VV0301371_Telit_Modules_Linux_USB_Drivers_User_Guide_r5.pdf ● http://ltehacks.com/viewtopic.php?t=649&start=10
● https://techship.com/faq/how-to-configure-telit-ln94-series-cellular-modules-to-qmi-mode- used-by-linux-systems-with-qmi-wwan-or-gobinet-driver/ ● https://lore.kernel.org/patchwork/patch/1159542/ ○ Kernel patch adding Foxconn VID/PID to the code ● XDA-Developers: Complete List of Qualcomm NV Items ○ NV value 457 and the checksum in 458. ■ IMEI is 14 digits ■ Checksum is single digit IMEI checksum (https://www.imei.info/calc) ○ 5077^"UNDP HSU VID PID"^"System*" ○ 5078^"UNDP HSU Manufacturer String"^"System*" ○ 5079^"UNDP HSU Product String"^"System*" ● QPST Tool - Backup IMEI and NVRAM configuration - Kate/Kenzo ○ Some more directions ● [HOW-TO][FIX] Repair your IMEI with QPST - updated w/ info ○ Link to QPST Tool QPST_2.7_378 which has NVRAM edit capability ● 4pda.ru thread ● https://github.com/bkerler/edl ○ tools to mess with device in EDL mode ● https://4pda.ru/forum/index.php?showtopic=994474&st=3080#entry100495708 ○ Directions for flashing LN940 ● edl.py by Bjoern Kerler ● Regional Versions ○ T77W968.00 (PH6K2) NA ○ T77W968.01 (59X27) WW ○ T77W968.02 (C0RVH) EU ○ T77W968.03 (K4DJ8) APAC ○ T77W968.04 (HMGJ3) China
Software & Downloads Driver/Firmware Packages ● 1.0.1.18.A01 ○ Release Notes ■ Fixed Device reboot 3 time during IMS re-register testing. ■ Fixed 3G-Roaming back to LTE causes auto Detach issue. ■ Updated firmware for AT&T, Verizon, Sprint and Generic GCF FW for ROW carriers. ○ Attempts firmware upgrade when installed ○ Image: T77W968.F1.0.0.4.9 ○ Contains QCMB_SDK_Tool.exe ● 1.0.1.24.A02 ○ Release Notes ■ Fixed the issue where the DW5821e device does not support modem standby feature. ■ Fixed the issue where the DW5821e device shows yellow exclamation during stress test and sleep mode. ■ Fixed the issue where the firmware switches between Verizon and Vodafone unexpectedly. ○ Image: T77W968.F0.0.0.2.6 ○ Contains QCMB_SDK_Tool.exe ● 1.0.1.30.A03 ○ Release Notes ■ Update FW to F1.0.0.3.5 ■ RF Tuner code update ○ No more QCMB_SDK_Tool.exe ● 1.0.1.31.A04 ○ Release Notes ■ Fixed WHQL issue with Win10 RS5/RS4 signed driver ■ Modify OTADM server from 4g.vzwdm.com to 4g2.vzwdm.com ■ Change AT&T OMADM HostID to 10JcjV83ZS for PTCRB ECO ● 1.0.1.32.A05 ○ Release Notes ■ Updated firmware to F1.0.0.3.5. ■ Updated the radio frequency (RF) Tuner code. ● 1.0.1.40.A08 ○ Release Notes ■ Fixed the issue where the wireless network is grayed out in Airplane mode. ■ Updated the firmware to version F1.0.0.4.2.AP.026. ● 1.0.1.51.A10
○ Release Notes ■ Fixed the issue where a system with Windows 10 May 2020 update shows no cellular network and fails to reconnect after it resumes from the hibernate mode. This issue occurs when a SIM that does not have PIN lock is connected to the system. ■ Updated the firmware to version F1.0.0.4.9.AP.033. ● 1.0.1.55.A11 ○ Release Notes ■ Fixed the issue where the SIM service is not activated after inserting the SIM card. ■ Updated the firmware to version F1.0.0.5.2.AP.035 ● 1.0.1.59.A13 ○ Release Notes ■ Fixed the issue where the WWAN firmware update stops during the update process and WWAN stops working. ■ Fixed the issue where the cellular network connection status that is displayed on the cellular icon on Windows Taskbar is incorrect. ● Other Tools ○ DW5821e Connection Manager Application 1.0.0.19.A02 ○ DW5821e GNSS Manager Application