Unlock SVP Lenovo Thinkpad T14 Gen2
Collapse
X
-
The MEC152x offers a software development system interface that includes a Trace FIFO Debug port, a host accessible serial debug port with a 16C550A register interface, a Port 80 BIOS Debug Port, and a 2-pin Serial Wire Debug (SWD) interface. Also included is a 4-wire JTAG interface used for Boundary Scan testing.
​Comment
-
Please help me to unlock this bios for Lenovo T14 2nd gen
Serial : HT4B0/HP4B0/HP5B1/HT4B2
NM-D353 Rev 3.0
Bios Chip serial: W25Q256JVEN
Serial Number : PF-443HPX
Attached FilesComment
-
Hello folks!
Can anyone help me with the BIOS for this model?
MB: NM-D352 Rev 1.0
SN:PF-3B5XV8
Type Number: 20W1-S2E400
BIOS dumps attached.
Attached FilesComment
-
Comment
-
Here is the output of the Segger software. I selected MEC1503 JTAG and all other configuration to auto.
From reading the logs, I'm wondering if I should also wire up the CPU reset nRESET_IN of the MEC to the Segger's RESET pin? From the schematics, it should be this (image with circle in red). The only thing that bugs me is that it is a direct connection from UTE1 (Thinkengine BD4179) to the MEC; there's only a pull up resistor on the line.
​
Comment
-
Were you able to solve it using Segger?Comment
-
I think you were addressing the question to me. No success with the Segger programmer. I rechecked all the connections and everything looks good.
Here is the output of the Segger software. I selected MEC1503 JTAG and all other configuration to auto.
From reading the logs, I'm wondering if I should also wire up the CPU reset nRESET_IN of the MEC to the Segger's RESET pin? From the schematics, it should be this (image with circle in red). The only thing that bugs me is that it is a direct connection from UTE1 (Thinkengine BD4179) to the MEC; there's only a pull up resistor on the line.
​
************************************************** ***********************************
Due to a lack of donations, server free space at a critical level, and possible closure of Bios Requests
all donations are welcome,
see the donate button at the bottom of the page, or
>>>>> click on this link to donate via PayPal. <<<<<
Every donation made will go towards server fees and maintenance costs.
************************************************** ***********************************Comment
-
I have found on one Russian Website that they are able to read the chip, but only if desoldered if i understood that correctly.
https://mslw.com/bb/showthread.php?t...c1503#pid97749Comment
-
they are also able to read NPCX797 and NPCX997 chip:
https://mslw.com/bb/showthread.php?t...cx797#pid94250
This is done with UFPI Tool:
https://mslw.com/product/ufpi-box-silver/Comment
-
they are also able to read NPCX797 and NPCX997 chip:
https://mslw.com/bb/showthread.php?t...cx797#pid94250
This is done with UFPI Tool:
https://mslw.com/product/ufpi-box-silver/************************************************** ***********************************
Due to a lack of donations, server free space at a critical level, and possible closure of Bios Requests
all donations are welcome,
see the donate button at the bottom of the page, or
>>>>> click on this link to donate via PayPal. <<<<<
Every donation made will go towards server fees and maintenance costs.
************************************************** ***********************************Comment
-
No, i am not using it, But i am planing to get the Programmer. NPCX Chips are supported without desoldering the chip. For the
MEC15xx and MEC17xx is only a matter of time when they wil also be supported without desoldering.
I am not sure what vertyanov is doing and if he is doiing anything to get the support for this chips.Comment
-
No, i am not using it, But i am planing to get the Programmer. NPCX Chips are supported without desoldering the chip. For the
MEC15xx and MEC17xx is only a matter of time when they wil also be supported without desoldering.
I am not sure what vertyanov is doing and if he is doiing anything to get the support for this chips.************************************************** ***********************************
Due to a lack of donations, server free space at a critical level, and possible closure of Bios Requests
all donations are welcome,
see the donate button at the bottom of the page, or
>>>>> click on this link to donate via PayPal. <<<<<
Every donation made will go towards server fees and maintenance costs.
************************************************** ***********************************Comment
-
Hi all, sorry I put the project on the shelf for the summer time and I redid part of my home lab so I wasn't able to do much for a few months.
So I caught up with trying the "CPU reset nRESET_IN of the MEC to the Segger's RESET pin" and it's a "no go". The entire motherboard resets and shuts down.
I've read the other posts and I cannot register to https://mslw.com​. They say: "Sorry, your email or IP matches that of a known spammer. If you feel this is a mistake, please contact an administrator." 😂
So I wasn't able to get more info.
I might be able to get a hold of a MEC1503 chip from a donor board. Would this work? The donor board doesn't have the exact same specs as mine. Or should I buy a blank one, find the a dump somewhere online, program it with the Segger and then solder it on?
I'm starting to wonder if it is possible to dump the MEC1503 reading all that was said since my last post.Comment
-
Just replace the MEC. This MEC doesnt have any firmware inside. The firmware for EC chip is inside BIOS. Check your bios with uefitool you will see a region call EC.Comment
-
According to this: https://docs.nordicsemi.com/bundle/n...doc/index.html
MEC152x is identical to MEC150x except for an enhanced Boot-ROM SPI loader.
So we can take a look at the MEC152X datasheet: https://ww1.microchip.com/downloads/...S00003427A.pdf
2K byte Internal EEPROM (MEC1523 Only) - Which should be present in the MEC1503 as well
So is the password stored there?
If it's the case, I was wondering if this approach would be a viable option:- Dump the BIOS
- Patch the BIOS to skip password checking popup
- Write the patched BIOS
- Boot and set a new blank password
- Write the original BIOS
Comment
-
The MEC has an EEPROM though.
According to this: https://docs.nordicsemi.com/bundle/n...doc/index.html
MEC152x is identical to MEC150x except for an enhanced Boot-ROM SPI loader.
So we can take a look at the MEC152X datasheet: https://ww1.microchip.com/downloads/...S00003427A.pdf
2K byte Internal EEPROM (MEC1523 Only) - Which should be present in the MEC1503 as well
So is the password stored there?
If it's the case, I was wondering if this approach would be a viable option:- Dump the BIOS
- Patch the BIOS to skip password checking popup
- Write the patched BIOS
- Boot and set a new blank password
- Write the original BIOS
Comment
Related Topics
Collapse
-
This specification for the Lenovo ThinkPad X1 Yoga + USB-C Dock Gen2 (40AS0090AU) Hybrid (2-in-1) can be useful for upgrading or repairing a laptop that is not working. As a community we are working through our specifications to add valuable data like the X1 Yoga + USB-C Dock Gen2 (40AS0090AU) boardview and X1 Yoga + USB-C Dock Gen2 (40AS0090AU) schematic. Our users have donated over 1 million documents which are being added to the site. This page will be updated soon with additional information. Alternatively you can request additional help from our users directly on the relevant badcaps forum....09-06-2024, 09:45 AM
-
This specification for the Lenovo ThinkPad X1 Yoga + USB-C Dock Gen2 (40AS0090AU) Hybrid (2-in-1) can be useful for upgrading or repairing a laptop that is not working. As a community we are working through our specifications to add valuable data like the X1 Yoga + USB-C Dock Gen2 (40AS0090AU) boardview and X1 Yoga + USB-C Dock Gen2 (40AS0090AU) schematic. Our users have donated over 1 million documents which are being added to the site. This page will be updated soon with additional information. Alternatively you can request additional help from our users directly on the relevant badcaps forum....09-06-2024, 09:40 AM
-
This specification for the Lenovo ThinkPad X1 Yoga + USB-C Dock Gen2 (40AS0090AU) Hybrid (2-in-1) can be useful for upgrading or repairing a laptop that is not working. As a community we are working through our specifications to add valuable data like the X1 Yoga + USB-C Dock Gen2 (40AS0090AU) boardview and X1 Yoga + USB-C Dock Gen2 (40AS0090AU) schematic. Our users have donated over 1 million documents which are being added to the site. This page will be updated soon with additional information. Alternatively you can request additional help from our users directly on the relevant badcaps forum....09-06-2024, 09:40 AM
-
This specification for the Lenovo ThinkPad X1 Yoga + USB-C Dock Gen2 (40AS0090AU) Hybrid (2-in-1) can be useful for upgrading or repairing a laptop that is not working. As a community we are working through our specifications to add valuable data like the X1 Yoga + USB-C Dock Gen2 (40AS0090AU) boardview and X1 Yoga + USB-C Dock Gen2 (40AS0090AU) schematic. Our users have donated over 1 million documents which are being added to the site. This page will be updated soon with additional information. Alternatively you can request additional help from our users directly on the relevant badcaps forum....09-06-2024, 09:40 AM
-
Lenovo ThinkPad X1 Carbon + ThinkPad USB 3.0 Pro Dock Notebook X Specification for Upgrade or RepairThis specification for the Lenovo ThinkPad X1 Carbon + ThinkPad USB 3.0 Pro Dock Notebook can be useful for upgrading or repairing a laptop that is not working. As a community we are working through our specifications to add valuable data like the X1 Carbon + ThinkPad USB 3.0 Pro Dock boardview and X1 Carbon + ThinkPad USB 3.0 Pro Dock schematic. Our users have donated over 1 million documents which are being added to the site. This page will be updated soon with additional information. Alternatively you can request additional help from our users directly on the relevant badcaps forum. Please...09-06-2024, 11:40 AM
- Loading...
- No more items.
Comment