Forum RSS Feed Follow @ Twitter Follow On Facebook

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[-]
Welcome
You have to register before you can post on our site.

Username:


Password:





[-]
Latest Threads
[REQUEST] Lenovo ThinkPad X201 (6QETxxWW...
Last Post: CK1968
Yesterday 10:10 AM
» Replies: 65
» Views: 53137
[REQUEST] Asus Zephyrus GX701GWR Bios un...
Last Post: Elijah Dannel
Yesterday 05:23 AM
» Replies: 8
» Views: 3791
[Request] Acer Aspire One 751h Bios Unlo...
Last Post: iggd
08-06-2026 12:51 AM
» Replies: 43
» Views: 41783
IBM Aptiva 2168 (Opti Viper) - CPU-Suppo...
Last Post: Geoman
08-04-2026 02:34 PM
» Replies: 0
» Views: 337
[REQUEST] X280 Bios Whitelist Removal
Last Post: compicat
08-04-2026 05:39 AM
» Replies: 0
» Views: 289
Foxconn 865G7MF Pinmodded Xeon Support
Last Post: KSM74
08-03-2026 08:21 AM
» Replies: 23
» Views: 3571
[REQUEST] LGA 771 on old ASUS mobo
Last Post: DeathBringer
08-02-2026 12:10 PM
» Replies: 10
» Views: 791
Advent Roma 2000/ECS I50IL1
Last Post: BootlegScarce
08-01-2026 09:05 PM
» Replies: 2
» Views: 5846
[REQUEST] Lenovo G70-70 BIOS Whitelist R...
Last Post: Dudu2002
08-01-2026 05:34 PM
» Replies: 135
» Views: 112021
[Request] Samsung Galaxy Book2 Pro (P12R...
Last Post: RafaelLVX
08-01-2026 01:18 PM
» Replies: 0
» Views: 379
[REQUEST]NEC Versapro VA-B(PC-VK22EAZCB)...
Last Post: mita-710
08-01-2026 05:49 AM
» Replies: 0
» Views: 369
[REQUEST] HP Pavilion DV6-2170 UEFI Bios...
Last Post: bernat77
07-31-2026 06:07 AM
» Replies: 2
» Views: 458
[REQUEST] Lenovo Thinkpad W540 & W541 (G...
Last Post: Profit21
07-31-2026 05:47 AM
» Replies: 52
» Views: 45336
NEC Versapro VA-B unlock&core 2 extreme ...
Last Post: mita-710
07-30-2026 08:45 PM
» Replies: 14
» Views: 1096
ThinkPad x240 bios corrupted
Last Post: grayreighn
07-30-2026 08:48 AM
» Replies: 2
» Views: 3247
[REQUEST] Lenovo ThinkCentre Edge 91z UE...
Last Post: maver3000
07-30-2026 03:10 AM
» Replies: 0
» Views: 466
[QUESTION] Modding an AMI bios to bypass...
Last Post: Machida96
07-29-2026 03:52 PM
» Replies: 11
» Views: 5656
[REQUEST] Acer Nitro 5 AN517-54 BIOS Unl...
Last Post: mistermu
07-29-2026 02:58 PM
» Replies: 30
» Views: 18954
[Removed, sp55068] Remove Whitelist for ...
Last Post: billydv
07-29-2026 11:33 AM
» Replies: 55
» Views: 92723
[REQUEST] Asus X53E (K53E) BIOS Unlock
Last Post: adrianfem
07-28-2026 08:33 PM
» Replies: 20
» Views: 9876

[REQUEST] AMI Aptio BIOS password Advantech UNO-1372G-J (UNOB-2117MB)
#1
Hello everyone,

I'm stuck on a BIOS password issue on an industrial embedded PC and would really appreciate some expert eyes on this. I've done what I can with hex editing but I think the real password check is elsewhere in the firmware, beyond my current skill level.

Hardware:

Device: Advantech UNO-1372G-J (industrial fanless PC / OPC)
Motherboard: UNOB-2117MB REV.A1, made in Taiwan, PN 19A3211703-01
CPU: Intel (embedded SoC, soldered)
Main BIOS flash chip: Winbond W25Q64JW (8MB, SOIC-8, 1.8V)

Problem:
The BIOS requires a password at boot/setup entry. Clearing CMOS (battery pull + CN36 clear-CMOS jumper + shorting battery socket V+/V-) has no effect on the password — as expected, since on these AMI Aptio boards it's stored in SPI flash rather than battery-backed CMOS.

What I've tried so far:


Dumped the main BIOS chip (W25Q64JW) via CH341A + 1.8V adapter + SOIC-8 clip. Read 3 times, MD5-verified identical each time.
Located what appears to be the AMI TSE (Total Setup Edition) password-related NVAR variables in the dump:

AMITSESetup NVAR entry (offset ~0x300281) with all-zero data (looks like a "default/empty" instance)
A second AMITSESetup NVAR entry (offset ~0x302931, size 0x68) containing non-zero data — what I assumed to be password hash material (80 bytes, structured as two overlapping ~40-byte sequences)
An OEMDEFAULTPWDSetup NVAR entry (offset ~0x302999) with a single data byte (0x04, later noticed value 0x70 depending on offset interpretation — I may have made an error here)

Tried zeroing the 64 then 80 bytes of the suspected hash data in the second AMITSESetup NVAR — reflashed, no change, password still requested.
Tried invalidating the NVAR entries entirely by changing the state byte from FF FF FF to 3C FF FF on both AMITSESetup and OEMDEFAULTPWDSetup entries — reflashed, verified the re-dump matched the written image exactly (MD5 identical), so the write itself succeeded with no write-protection issue — but the password prompt is still there.

So the chip write/erase/verify cycle works fine (no WP/lock issue), but neither approach neutralizes the actual password check. My guess is either:

The AMITSESetup varstore I found is just the general Setup form storage (all BIOS settings), not specifically the password, and the real password hash is stored/checked elsewhere (different GUID, different NVAR name, or computed by DXE/PEI driver code rather than a plain stored hash)
There's some checksum/CRC over the NVRAM volume that needs to be recalculated after modification, and an invalid checksum causes the driver to fall back to a "locked" state rather than "no password"

What I'm hoping for:


Guidance on identifying the correct NVAR GUID/variable that AMI Aptio uses for password verification, as opposed to general Setup storage
Whether AMIBCP (AMI BIOS Configuration Program) can open/patch this dump properly, since UEFITool NE reports "Stores not found" on this image
Any known quirks specific to Advantech's AMI Aptio implementation


I have the original untouched dump and full change logs for every attempt. Happy to upload the original .bin if that helps, and I can provide any additional dumps/photos of the board on request.

Thanks in advance for any pointers!
find
quote


Forum Jump:


Users browsing this thread: 1 Guest(s)