Unlock SVP Lenovo Thinkpad T14 Gen2

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • speed488
    Member
    • Feb 2024
    • 10
    • Canada

    #41
    Originally posted by anhbanxoi

    2KB EEPROM just for serial, model, bios password. Laptop still can turn on without those informations. You can later program it with U1 tool
    OK so that is it. This is why people focus around the MEC1503: because the BIOS password is saved there.
    But, from what you are saying, just replacing the MEC1503 with a blank one should work to unlock the unit?

    Comment

    • TiagoNecer
      Member
      • Nov 2022
      • 10
      • Brasil

      #42
      I already tried to buy a new chip (blank) on aliexpress, I changed it and the board didn't turn on, I only did the test, trying once, has anyone ever managed to make this procedure work?

      Comment

      • CJ Mangasep
        New Member
        • Oct 2024
        • 1
        • Philippines

        #43
        Hello, I am asking those who know a way to remove the supervisor/bios password for my laptop

        HTB40/HP4B0/HT5B1/HP5B1/HT4B2 NM-D353 Rev:1.0

        serial number: PF-3NA82Y
        type number: 20W5-S0NH00

        Should I do some kind of shorting the chips? In that case which one should i short?
        Or should i do some kind of programming?

        Thank you

        Comment


        • peste
          peste commented
          Editing a comment
          post merged..
      • acedogblast
        Senior Member
        • Feb 2023
        • 56
        • USA

        #44
        Hello I can confirm that replacing MEC1503 chip with another from a laptop without SVP does work. You can see how I did it in my post here: https://www.badcaps.net/forum/troubl...-and-x13-gen-2

        Comment

        • cgtec
          Senior Member
          • Feb 2014
          • 54
          • algeria

          #45
          Originally posted by speed488

          The MEC has an EEPROM though.

          According to this: https://docs.nordicsemi.com/bundle/n...doc/index.html
          MEC152x is identical to MEC150x except for an enhanced Boot-ROM SPI loader.

          So we can take a look at the MEC152X datasheet: https://ww1.microchip.com/downloads/...S00003427A.pdf
          2K byte Internal EEPROM (MEC1523 Only) - Which should be present in the MEC1503 as well

          So is the password stored there?

          If it's the case, I was wondering if this approach would be a viable option:
          • Dump the BIOS
          • Patch the BIOS to skip password checking popup
          • Write the patched BIOS
          • Boot and set a new blank password
          • Write the original BIOS
          Am I missing or overlooking something?
          you can not path bios .... any more

          Comment

          • cgtec
            Senior Member
            • Feb 2014
            • 54
            • algeria

            #46
            Originally posted by Mudau
            Re: Unlock SVP Lenovo Thinkpad T14 Gen2



            I did try with Nm-d351 schematic and boardview to locate jtag, my board was nm-d352, these boards looks identical.
            it only read once(rt809f), then stopped reading chip due to low voltage(3v),
            the customer took the machine before i can add the 10k resistors for 3v.

            you can try it out maybe you can win.
            [Mod. Edit] Schematic and boardview -> https://www.badcaps.net/forum/showth...77#post1248377

            Reminder: rules and organization of this section
            https://www.badcaps.net/forum/showthread.php?t=117483
            to enable jtag need script . most work on this chip use SWD .....

            Comment

            Related Topics

            Collapse

            Working...