-
Notifications
You must be signed in to change notification settings - Fork 57
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Added firmware for DGA0122 VCNT-P Telia Lithuania #233
Added firmware for DGA0122 VCNT-P Telia Lithuania #233
Conversation
Temporary Dropbox link for torrent seeders: https://www.dropbox.com/s/gukgtjcfyufstn0/DGA0122-VCNT-P-19.4.0539-4521016-Signed.rbi.zip?dl=0 |
Resolves: 142 ? |
@tosiara I have the same router with which I would like to play. Actually I want to change default DNS on this router, and maybe connect it to VPN service to be able to share connection through VPN for this router clients. Could you please help me root it? You wrote that there is SSH backdoor on port 60022, but it is closed. NMAP Intense scan results: 53/tcp open domain Cloudflare public DNS Router info: |
Sorry, I no longer have access to that router. And I only got a temporary root access with a help of Telia engineer. |
I'm ready to merge this but I have some doubts it could resolve #142 since it is related to non-telia variant. We used to have Telia devices signed by Telia specific OSIK (and also a different OSCK). This means the OSCK you shared is likely coupled to Telia OSIK and therefore the VCNT-P board owned by @protonbeam is not accepting this firmware. We can determine by running signature check on the RBI you shared using Telia OSIK which we have already in this repo. I also need an explaination of this firmware being of Type 1. Type 1 means you can get it downgraded via software (without BOOTP/TFTP) to a Type 2 one. It is probably better to flag this as type ??? |
Maybe, we need to get confirmation from Protonbeam regarding this one. At least try Wireshark to see if it really gets into BOOTP/TFTP and really downloads the RBI
In this PR I have marked the firmware as Type 2. Please clarify your question |
I'm going to merge this now, but the only listed firmware has been stated to be of type 1 without any other available type 2 images. I will revert that indication to Type ??? to avoid ambiguity. Also, we know there is a 19.4.0200-4521014 from above bank info for which we have no RBI nor raw dump. |
* Existing VCNT-P OSCK is for Telia * Added firmware for DGA0122 VCNT-P Telia Lithuania (#233) * Change VCNT-P listed firmware to type ??? * Added Telstra Smart Modem Gen 3 (CobraXh) (#262) * Added Telstra Smart Modem Gen 3 * Changed reference to ARM64 boards * Reverted RBI change + changed PKGTB to ref U-boot * Cannot restore ubifs rootfs_data dump * Added 20.3.c.0432-MR21.1-RA for vbnt-v and vcnt-a (#266) * Add new Firmware for DGA0122 (#270) --------- Co-authored-by: LuKePicci <luca.piccirillo@gmail.com> Co-authored-by: tosiara <tosiara@users.noreply.github.com> Co-authored-by: Luca Piccirillo <LuKePicci@users.noreply.github.com> Co-authored-by: Stephen Stevens <41851175+seud0nym@users.noreply.github.com> Co-authored-by: Lorenzo <44505255+lorenzocanalelc@users.noreply.github.com>
DGA0122 VCNT-P
This router is provided by Telia Lithuania ISP under a model name "Telia X1"
Official manual: pdf
Photo:
Bacis specs:
Type 2 firmware, locked. No strategy known yet.
CWMP ACS connection is hardcoded to a list of https urls, connection requires a client cert:
Classic Telia backdoors available on ports:
Post-root config re-encryption exploit works. However, "Configuration" section is hidden from the web UI, requires manual curl connection.
Some info from root shell: