PDA

View Full Version : INSEEGO wavemaker FW2000e AND FW2000 HACKING AND INFO THREAD



rich hathaway
05-08-2023, 07:29 AM
I just got one of these a few days ago and have been at it for a few days now.
This thing is a beast!
Here are some facts about it taken from the official datasheet which I will attach for reference.

Network Connectivity*
• 5G sub-6 GHz
• 4G LTE Cat 22
• 4x4 MIMO sub-6 GHz
• 256 QAM sub-6 GHz
Bands Supported
• 5G NR: n1/n2/n3/n5/n7/n12/n20/n25/n28/n38/
n40/n41/n46/n48/n66/n71/n77/n78
• 4G LTE: B1/B2/B3/B4/B5/B7/B8/B12/B13/B14/
B17/B20/B25/B26/B28/B29/B30/B32/B38/B39/
B40/B41/B42/B43/B46/B48/B66/B71
• Band support varies by regional SKU
Chipset
• Qualcommฎ Snapdragon™ SDX55
Ports
• (1) 5Gbps Ethernet LAN port
Power
• Power over Ethernet (PoE) - 802.3bt Type 3
High Gain Antennas
• 14dBi: 3.3GHz - 4.2GHz
• 12dBi: 1.7GHz - 2.7GHz
• 5dBi: 1.5GHz
• 0-4dBi: 600MHz - 1.0GHz
=================================
its big, bulky and heavy, weighing in at about 10 lbs, but this enclosure has it all (imho) if you can get by the size
and weight, I have it inside my house at the moment and it works just fine, hope it not giving me brain cancer or something with its awesome power lolol.
So the guy that sent it to me was wanting me to perform some magic with the IMEI, ESN, MEID & FID and then make a patch and hard code the TTL and then there are some functions missing from the admin page such as IPPT, APN, Network Technologies etc. That needed to be added back in so the end user can adjust as needed.
this device basically has the same firmware as the M2000 and is even byte by byte identical in most/alot of it.
It even references itself as a M2000 and in some cases A mifi 8xxx.
It came with the ports enabled already via the micro usb port so that cut out alot of work right there.

Most of the technical stuff is similar to all the new class of inseego devices as far as reading/writing to the baseband with the exception of the user interface has a watchdog now. I guess this what they are calling their
"
Security
• 3rd Party cybersecurity penetration testing verified
• Security hardened web interface "

what I say to that is
lets rebrand it!


[Only registered and activated users can see links] ([Only registered and activated users can see links])


and added some of the fields they left out
such as MDN,MEID,ESN,SID,ERI,PRL



[Only registered and activated users can see links] ([Only registered and activated users can see links])

enabled some hidden menus


[Only registered and activated users can see links] ([Only registered and activated users can see links])

They had the IPV6 boolean blocked, I enabled it and made it visible again

[Only registered and activated users can see links] ([Only registered and activated users can see links])


They hid the advanced menu so I un-hid it


[Only registered and activated users can see links] ([Only registered and activated users can see links])

so after all this and with the magic and TTL patch done this thing is blazing fast, I am in the middle of the woods in Kansas
and this is what I am getting with 2 bars of signal (-122)

[Only registered and activated users can see links] ([Only registered and activated users can see links])

I flashed one remotely for the guy that sent me this one and here is his results


[Only registered and activated users can see links] ([Only registered and activated users can see links])
continued in next post

rich hathaway
05-08-2023, 07:38 AM
They have this thing dumbed down to max streaming rate of 720p as you can see here


[Only registered and activated users can see links] ([Only registered and activated users can see links])




so got that patched, now this the video speed rate now



[Only registered and activated users can see links] ([Only registered and activated users can see links])


below is some info about it such as partition names and such

[Only registered and activated users can see links] ([Only registered and activated users can see links])


and hardware id's so you can know what drivers to use/load for each
MODEM
USB\VID_05C6&PID_90B6&REV_0414&MI_02
USB\VID_05C6&PID_90B6&MI_02
-------------------------------------------------------
HID
USB\VID_05C6&PID_90B6&REV_0414&MI_05
USB\VID_05C6&PID_90B6&MI_05
-------------------------------------------------------
RNDIS
USB\VID_05C6&PID_90B6&REV_0414&MI_00
USB\VID_05C6&PID_90B6&MI_00
-------------------------------------------------------
DIAG
USB\VID_05C6&PID_90B6&REV_0414&MI_03
USB\VID_05C6&PID_90B6&MI_03
-------------------------------------------------------
ADB
USB\VID_05C6&PID_90B6&REV_0414&MI_04
USB\VID_05C6&PID_90B6&MI_04
-------------------------------------------------------
USB COMPOSITE DEVICE
USB\VID_05C6&PID_90B6&REV_0414
USB\VID_05C6&PID_90B6
--------------------------------------------------------

dev: size erasesize name
mtd0: 00280000 00040000 "sbl"
mtd1: 00280000 00040000 "mibib"
mtd2: 01500000 00040000 "efs2"
mtd3: 001c0000 00040000 "tz"
mtd4: 00100000 00040000 "tz_devcfg"
mtd5: 00180000 00040000 "ddr"
mtd6: 00100000 00040000 "apdp"
mtd7: 00100000 00040000 "xbl_config"
mtd8: 00100000 00040000 "multi_image"
mtd9: 00100000 00040000 "aop"
mtd10: 00100000 00040000 "qhee"
mtd11: 00100000 00040000 "abl"
mtd12: 00280000 00040000 "uefi"
mtd13: 00180000 00040000 "toolsfv"
mtd14: 00180000 00040000 "loader_sti"
mtd15: 00d00000 00040000 "boot"
mtd16: 00100000 00040000 "scrub"
mtd17: 06b40000 00040000 "modem"
mtd18: 001c0000 00040000 "misc"
mtd19: 00180000 00040000 "devinfo"
mtd20: 01900000 00040000 "recovery"
mtd21: 001c0000 00040000 "fota"
mtd22: 02b00000 00040000 "recoveryfs"
mtd23: 00100000 00040000 "sec"
mtd24: 00100000 00040000 "fotacookie"
mtd25: 11200000 00040000 "system"


Please post your findings about this device
I will have a few extras to sell and will post them in the marketplace in a few days as time permits
here is the data sheet for it


[Only registered and activated users can see links] ([Only registered and activated users can see links])