Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 D-Link DPN-FX3060V GPON WiFi Router, (Nijika) Firmware Community Modding

views
     
TSAnime4000
post Sep 6 2024, 02:16 AM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(syahpian @ Sep 6 2024, 12:04 AM)
nope, me on normal home unifi plan
*
odd, the way VLAN is provision is not same as me even same OLT, haha
TSAnime4000
post Sep 13 2024, 02:05 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(OKLY @ Sep 13 2024, 12:24 PM)
Out of curiosity, who is responsible to patch the known CVEs? Can we report it to somebody?
*
have told TM and still no answer, I guess they don't care
TSAnime4000
post Sep 13 2024, 07:30 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(enduser @ Sep 13 2024, 06:59 PM)
Maybe can open ticket at cyber security malaysia?

https://www.cybersecurity.my/en/index.html
*
I try to compile required document, but... only I know, thing some one in Hack GPON group didn't disclose the exploit, so I can't report this as I don't know how to replicate their exploit
TSAnime4000
post Sep 20 2024, 02:40 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


blstz like OKLY said, just use old ONT since you are on 1G plan, this much better then use D-Link on random issue later on
TSAnime4000
post Sep 20 2024, 08:57 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(blstz @ Sep 20 2024, 06:53 PM)
i see.

would you know if the suspected “unbinding” is done locally on the old ONU (remove settings) or is it done on TM “infrastructure” side.

asking coz wanna know what to look out for. later technician setup new onr and in the process “unbinds” old onu 😅 anything i can do to make sure this doesn’t happen?
*
you need ask to not bind the Serial Number,

however, you can copy D-Link SN to old ONU, like Huawei HG8240H (or H5) can set S/N, just use D-Link S/N
TSAnime4000
post Oct 16 2024, 07:47 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(OKLY @ Oct 16 2024, 05:59 PM)
Aware that TM is now providing a newer v2.0.3 firmware, irregardless whether they solved the speed drop issue when using bridge mode, are the CVEs patched?
*
nope, one of my friend overseas still can enter even in v2.0.3, even they get WG working by back porting the kernel.

D-Link now become VPN point for them xD
TSAnime4000
post Oct 16 2024, 08:30 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(OKLY @ Oct 16 2024, 08:21 PM)
Oh my.. sweat.gif

Can’t help but wonder if they purposely don’t patch the CVEs due to some other motives..
*
that's a mystery,

either they don't know, or already patch but still there, or they don't care since because sold to TM cheap cheap

what I can told from my friend, they just say "not using known CVE", I guess they found a way to attack D-Link remotely even NATed via VLAN 209 to find another D-Link ONR.

whatever it is, ISP equipment is never been secure

TM not paid enough to maintain security since.

many people already using own Router that managed by Asus, TP-LINK, Mikrotik, Ubiquiti, etc... that have active security patches.

I know VLAN209 is for management, for good.
but once got a weak point, it come a checkpoint to crawl deeper within ISP private network

that is why old ONU Bridge since we been using are fine and never been use as Internet Routing.

all of sudden Unifi also offer ONR solution, trade off security for cheaper internet
TSAnime4000
post Oct 16 2024, 09:57 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(mus6677 @ Oct 16 2024, 09:47 PM)
are the firmware file v2.0.3 available? we can flash it ourself?
*
No, I can't upload that, sadly you need ask TM technician for that
TSAnime4000
post Oct 16 2024, 11:35 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(OKLY @ Oct 16 2024, 10:27 PM)
So it's kinda like still in beta stage and they are not pushing it to everyone yet?
*
apparently, just to be safe
still, not to use ISP equipment if concern about security sweat.gif

since DNS debacle, many overseas companies who use 2Gbps plan, use my PON Stick,
they don't trust TM because anytime mcmc can force ISP to push stock DNS via OMCI or TR069
TSAnime4000
post Oct 27 2024, 03:29 AM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(emilyngsc @ Oct 24 2024, 10:57 AM)
Anime4000 any update for new firmware? Thanks
*
I working on patching the firmware, just now I got a screenshot where D-Link DPN-FX3060V_2.0.3 successfully exploited

Screenshot, blur sensitive information

user posted image

user posted image

It appear using msf6 (Metasploit Framework) apart from their RAT (Remote Access Tools), where msf code just striped down from RAT

but it appear the D-Link can be pawned

what more dangerous, can override Inactive Firmware partition as you see at last command, where:

1. Check current active partition, it appear partition 1 (secondary) is active as V2.0.3 installed.
2. Use 'NC' to accept connection and pipe hacked firmware to inactive partition 0 (primary) where V2.0.2 is reside
3. Attacker can force to boot hacked firmware and clone to another partition

In order patching these exploit, I need their code, at least strip down msf code

or

remove all cloud stuff, disable TR142, TR069, and other stuff.

even in Bridge mode, this exploit has multiple stages and can find more victim via VLAN209 and 400

the thing is, I didn't give V2.0.3 to them, somehow they manage to get it, what they told me, same exploit can be use

this D-Link pawned has been sold in zero day market... because potential money generator, aka VPN Node, Botnet, etc... since who own D-Link is has high speed internet...

...

I no idea then, only way to save D-Link is,
by remove everything and dumb down as DUMB ONT Bridge! No Routing, No ISP Management, No WiFi

what do you think?
TSAnime4000
post Oct 27 2024, 05:23 AM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(enduser @ Oct 27 2024, 03:52 AM)
i think tm nut should take responsibility on this

How many gpon router now already been use ready to be exploited,.
*
I don't think so, to make internet cheap, device security is second. (not paid enough to maintain security)
for example, cheap router like TOTO LINK, don't care vulnerability
can't be sure how many, but plenty compromised device around the world
with right fingerprint, can found on Shodan IoT search engine
TSAnime4000
post Nov 3 2024, 09:48 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(shahzad86 @ Nov 3 2024, 03:02 PM)
Hi All, i got upgraded from 800mbpsto 1GBps & was given black modem/router, which I honestly regretted this decision. The 5GHz performance and reliability has been worse than previous setup. I have to change to 2.4Ghz everytime upstairs to get Internet to work. I still have old modem & router, if I change back to old setup, is it plug & play or need much configuration?
*
just plug old one, no config needed
TSAnime4000
post Nov 16 2024, 06:51 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


I put OpenSpeedTest inside D-Link DPN-FX3060V:



just dumb, the boa web server not that fast, not multi threading, and upload cannot work
TSAnime4000
post Nov 18 2024, 04:26 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


with my spare time, I improved the stock firmware, as usual I port PON Stick to here, planning make bridge mode only

user posted image

I add "Nijika OS" to display hardware info, MIB and OMCI stuff

still, I wont patch the vulnerability, so many binary related to each other
TSAnime4000
post Nov 19 2024, 11:49 AM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


After modding to make D-Link ONR become dumb (ONT Bridge), porting the PON Stick files into D-Link and recompile, now testing

Dumb D-Link Wireless is disabled, No Router, No NAT, just bridge with ME 171 override
user posted image

Login Screen
user posted image

Nijika OS
user posted image

VLAN
user posted image

I not sure why Nokia OLT suddenly push VLAN 500 into VEIP? what's make it? previously don't have:
user posted image

Note: TM is clear on this, flashing modded firmware will invalidate the warranty, so, this firmware will push -NIJIKA prefixes into OMCI message.
TSAnime4000
post Feb 5 2025, 06:54 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


user posted image

I have earlier,
during Binary Diff, still contain vulnerable, cause I not share bad firmware
TSAnime4000
post Feb 20 2025, 11:42 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


Another Update,

It appear that Zyxel also make ONR, and use same SoC and board as D-Link DPN-FX3060V A1 hardware!!!

user posted image

user posted image

UBoot Init
D-Link A1:
CODE

NOTICE:  Booting Trusted Firmware - Realtek Semiconductor Corp.
NOTICE:  BL1: v1.5(release):TAURUS_TAPEOUT_2_0
NOTICE:  BL1: Built : 17:13:20, Oct 27 2021
NOTICE:  BL1: CPU Speed 1000 MHz
NOTICE:  GLOBAL_STRAP 0xc0a
NOTICE:  boot from serial NAND flash
NOTICE:  SPI_NAND: MT29F2G01ABAGDWB/F50L2G41XA/XT26G02ELGIGA 0x2c24
NOTICE:  SPI_NAND: Page 0x800, Block 0x20000, Chip 256MB
NOTICE:  SPI_NAND: plane_select=0x40, plane_select_bit=0x1000
NOTICE:  Platform initialized
NOTICE:  ROTPK undeployed
NOTICE:  BL1: Booting BL2
NOTICE:  BL2: RTL9607DQ CPU Speed 1000 MHz
NOTICE:  boot from serial NAND flash
NOTICE:  BL2: SPI_NAND: MT29F2G01ABAGDWB/F50L2G41XA/XT26G02ELGIG/WSFVC32GBID 0x2c24
NOTICE:  BL2: SPI_NAND: Page 0x800, Block 0x20000, Chip 256MB
NOTICE:  BL2: SPI_NAND: plane_select=0x40, plane_select_bit=0x1000
...
U-Boot 2020.01-00005-g2117f28170 (Mar 08 2023 - 11:54:55 +0800)Taurus-SoC


Zyxel:
CODE

NOTICE:  Booting Trusted Firmware - Realtek Semiconductor Corp.
NOTICE:  BL1: v1.5(release):TAURUS_TAPEOUT_2_0
NOTICE:  BL1: Built : 17:13:20, Oct 27 2021
NOTICE:  BL1: CPU Speed 1000 MHz
NOTICE:  GLOBAL_STRAP 0xc0a
NOTICE:  boot from serial NAND flash
NOTICE:  SPI_NAND: W25N04KV 0xefaa23
NOTICE:  SPI_NAND: Page 0x800, Block 0x20000, Chip 512MB
NOTICE:  Platform initialized
NOTICE:  BL1: Booting BL2
NOTICE:  BL2: RTL9607DQ
NOTICE:  boot from serial NAND flash
NOTICE:  BL2: SPI_NAND: W25N04KVZEIE 0xefaa23
NOTICE:  BL2: SPI_NAND: Page 0x800, Block 0x20000, Chip 512MB
...
U-Boot 2020.01-svn22550 (Oct 07 2024 - 07:57:17 +0000)Taurus-SoC


Booting Kernel
D-Link A1:
CODE

Starting kernel ...

[    0.000000] Booting Linux on physical CPU 0x0000000000 [0x412fd050]
[    0.000000] Linux version 5.10.70 (wen_peng@ubuntu) (aarch64-linux-gcc (Realtek ASDK64-10.2.0 Build 3544) 10.2.0, GNU ld (Realtek ASDK64-10.2.0 Build 3544) 2.35.1.20201230) #1 SMP Wed Mar 8 11:56:34 CST 2023


Zyxel:
CODE

Starting kernel ...

[    0.000000] Booting Linux on physical CPU 0x0000000000 [0x412fd050]
[    0.000000] Linux version 5.10.138 (square@cdd59d47d0ed) (aarch64-openwrt-linux-gnu-gcc (OpenWrt GCC 11.2.0 r0+19487-2a59b851ac) 11.2.0, GNU ld (GNU Binutils) 2.37) #0 SMP Fri Dec 13 02:02:44 2024


Inside Zyxel
user posted image

WebGUI Zyxel
user posted image

---

Well, I waiting for him to dump NAND Flash, so we can build proper OpenWRT for D-Link A1 and Zyxel ONR.

Since using OpenWRT, no more exploit thumbup.gif
TSAnime4000
post Feb 21 2025, 12:47 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(kwss @ Feb 21 2025, 09:48 AM)
Anime4000
Did the Zyxel has the same GPON SoC as the D-Link?
Is the Zyxel an off the shelf ONR or is it specifically customized for ISP?

The problem with a lot of OpenWRT porting is the board cannot use vanilla kernel due to binary blob.
The specific roadblock I can see in D-Link ONR is all the proprietary initialization sequence are in startup binary. Maybe you can swap those with your own one from PON stick.

But since you have the Realtek SDK, does it comes with the toolchain for the GPON SoC?
*
Zyxel and D-Link both use same SoC and same Taurus reference board, what I checked for now, only D-Link A1 hardware share quite a lot similarly.

we just have incomplete reverse engineer SDK

but, compile for ARM64 not that hard, like Zyxel did, use OpenWRT tool chain,

see if can use Zyxel kernel and driver on D-Link, if required patching, so be it.

let say DPN-FX3060V A1 has completed OpenWRT Build, still can't update firmware via WebGUI, need flash directly into NAND
TSAnime4000
post Feb 21 2025, 02:52 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(kwss @ Feb 21 2025, 01:24 PM)
Do both Zyxel and D-Link has the same mtdblock layout?
If yes then it should be just re-use the "dtb" and "kimage" from D-Link.
Replace all the kernel module in Zyxel "rootfs" with D-Link and it should just boot?

Maybe copy over those OEM config from D-Link too, as it contains the hardcoded mesh key, VoIP config, etc?
*
since both use UBI underlying MTD, and Zyxel ONR can't login root yet, so MTD layout is unknown.

in group said, is possible just copy Zyxel to D-Link as is, they theories it will boot
TSAnime4000
post Feb 23 2025, 03:38 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(hsbb @ Feb 23 2025, 10:13 AM)
ZTE F620 also use same Micron 256MB NAND ic (0x2c24) like DPN-FX3060V A1.
*
How about SoC, it is ZTE own ARM CPU ?

3 Pages < 1 2 3 >Top
 

Change to:
| Lo-Fi Version
0.0233sec    0.47    7 queries    GZIP Disabled
Time is now: 28th November 2025 - 01:45 AM