Forum RSS Feed Follow @ Twitter Follow On Facebook

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[-]
Welcome
You have to register before you can post on our site.

Username:


Password:





[-]
Latest Threads
Extracting BIOS - Samsung Galaxy Book 3 ...
Last Post: mirroreduser
Today 09:12 AM
» Replies: 0
» Views: 17
[REQUEST] HP Pavilion g6-1b87cl WiFi Whi...
Last Post: AkiNakano6055
Today 12:32 AM
» Replies: 0
» Views: 57
Asrock Z890-C Bios Mod
Last Post: xul8tr
Yesterday 12:51 PM
» Replies: 0
» Views: 121
[REQUEST] Lenovo G580 (5ECNxxWW) Whiteli...
Last Post: frozik1990
Yesterday 11:55 AM
» Replies: 1735
» Views: 1221880
[REQUEST] Acer Aspire VN7-791(G) BIOS Un...
Last Post: Whiter
Yesterday 06:19 AM
» Replies: 92
» Views: 118878
Modifying Aptio V BIOS to disable non-fa...
Last Post: KappaDev
09-30-2026 09:16 PM
» Replies: 0
» Views: 151
[Unlocked] Acer Aspire One D255E
Last Post: ananinami
09-29-2026 01:26 PM
» Replies: 3
» Views: 6634
FANPEEC S210 i9-10980HK
Last Post: geometryczny@tlen.pl
09-29-2026 07:14 AM
» Replies: 0
» Views: 257
[REQUEST] Lenovo Z410 & Z510 (8DCNxxWW) ...
Last Post: anntoxx
09-28-2026 02:28 PM
» Replies: 504
» Views: 308899
[REQUEST] Lenovo Y70-70 (9ECNxxWW) White...
Last Post: Dooglas
09-27-2026 11:31 AM
» Replies: 92
» Views: 61707
[REQUEST] Lenovo E31-70 (AFCNxxWW) BIOS ...
Last Post: kristian6237455372
09-27-2026 11:04 AM
» Replies: 2
» Views: 444
[REQUEST] HP dv6-6c51ca whitelist remova...
Last Post: johnyn2005
09-26-2026 12:52 PM
» Replies: 20
» Views: 20086
[REQUEST] Lenovo B590 (H5ETxxWW) Whiteli...
Last Post: katri
09-26-2026 02:03 AM
» Replies: 281
» Views: 168763
[Request] Dell Optiplex 3040M 7th Gen CP...
Last Post: DeathBringer
09-25-2026 12:35 AM
» Replies: 10
» Views: 6119
[Untested] Dell OptiPlex 3040 H110 – Cof...
Last Post: gonza20889
09-23-2026 02:02 PM
» Replies: 0
» Views: 654
[REQUEST] Acer TravelMate B113-E BIOS Un...
Last Post: rt400
09-22-2026 07:39 AM
» Replies: 9
» Views: 5613
[REQUEST] Acer Aspire 8930(G) BIOS Unloc...
Last Post: xeper8x8
09-21-2026 10:04 PM
» Replies: 59
» Views: 60903
How To Add SLIC 2.1 To An Intel Motherbo...
Last Post: Argogo
09-21-2026 11:15 AM
» Replies: 75
» Views: 274792
Advanced BIOS Unlock machenike l15p
Last Post: ztazzy
09-20-2026 09:28 PM
» Replies: 0
» Views: 766
[REQUEST] Hystou S200 BIOS unlock
Last Post: Onyicho
09-20-2026 05:58 PM
» Replies: 33
» Views: 24730

[REQUEST] AMI Aptio BIOS password Advantech UNO-1372G-J (UNOB-2117MB)
#1
Hello everyone,

I'm stuck on a BIOS password issue on an industrial embedded PC and would really appreciate some expert eyes on this. I've done what I can with hex editing but I think the real password check is elsewhere in the firmware, beyond my current skill level.

Hardware:

Device: Advantech UNO-1372G-J (industrial fanless PC / OPC)
Motherboard: UNOB-2117MB REV.A1, made in Taiwan, PN 19A3211703-01
CPU: Intel (embedded SoC, soldered)
Main BIOS flash chip: Winbond W25Q64JW (8MB, SOIC-8, 1.8V)

Problem:
The BIOS requires a password at boot/setup entry. Clearing CMOS (battery pull + CN36 clear-CMOS jumper + shorting battery socket V+/V-) has no effect on the password — as expected, since on these AMI Aptio boards it's stored in SPI flash rather than battery-backed CMOS.

What I've tried so far:


Dumped the main BIOS chip (W25Q64JW) via CH341A + 1.8V adapter + SOIC-8 clip. Read 3 times, MD5-verified identical each time.
Located what appears to be the AMI TSE (Total Setup Edition) password-related NVAR variables in the dump:

AMITSESetup NVAR entry (offset ~0x300281) with all-zero data (looks like a "default/empty" instance)
A second AMITSESetup NVAR entry (offset ~0x302931, size 0x68) containing non-zero data — what I assumed to be password hash material (80 bytes, structured as two overlapping ~40-byte sequences)
An OEMDEFAULTPWDSetup NVAR entry (offset ~0x302999) with a single data byte (0x04, later noticed value 0x70 depending on offset interpretation — I may have made an error here)

Tried zeroing the 64 then 80 bytes of the suspected hash data in the second AMITSESetup NVAR — reflashed, no change, password still requested.
Tried invalidating the NVAR entries entirely by changing the state byte from FF FF FF to 3C FF FF on both AMITSESetup and OEMDEFAULTPWDSetup entries — reflashed, verified the re-dump matched the written image exactly (MD5 identical), so the write itself succeeded with no write-protection issue — but the password prompt is still there.

So the chip write/erase/verify cycle works fine (no WP/lock issue), but neither approach neutralizes the actual password check. My guess is either:

The AMITSESetup varstore I found is just the general Setup form storage (all BIOS settings), not specifically the password, and the real password hash is stored/checked elsewhere (different GUID, different NVAR name, or computed by DXE/PEI driver code rather than a plain stored hash)
There's some checksum/CRC over the NVRAM volume that needs to be recalculated after modification, and an invalid checksum causes the driver to fall back to a "locked" state rather than "no password"

What I'm hoping for:


Guidance on identifying the correct NVAR GUID/variable that AMI Aptio uses for password verification, as opposed to general Setup storage
Whether AMIBCP (AMI BIOS Configuration Program) can open/patch this dump properly, since UEFITool NE reports "Stores not found" on this image
Any known quirks specific to Advantech's AMI Aptio implementation


I have the original untouched dump and full change logs for every attempt. Happy to upload the original .bin if that helps, and I can provide any additional dumps/photos of the board on request.

Thanks in advance for any pointers!
find
quote


Forum Jump:


Users browsing this thread: 1 Guest(s)