Forum RSS Feed Follow @ Twitter Follow On Facebook

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[-]
Welcome
You have to register before you can post on our site.

Username:


Password:





[-]
Latest Threads
[REQUEST] Acer PT715-51 (Triton 700) ins...
Last Post: deepseek
Today 06:51 AM
» Replies: 30
» Views: 23951
Sony VAIO SVE1711X1EB: looking for the o...
Last Post: solaris2010
Yesterday 02:20 PM
» Replies: 0
» Views: 114
[REQUEST] Alienware M15 R7 i7-12700H BIO...
Last Post: Carl Camargos
Yesterday 11:42 AM
» Replies: 2
» Views: 1824
[REQUEST] Acer Aspire E1-531(G) BIOS Unl...
Last Post: AlbertWesker
08-24-2026 04:13 PM
» Replies: 104
» Views: 86187
Clevo P775TM1-G BIOS
Last Post: kiratdeluxe
08-24-2026 07:30 AM
» Replies: 163
» Views: 148004
Could the ASUS P6T Deluxe be given UEFI ...
Last Post: matthewacbroad
08-23-2026 08:29 AM
» Replies: 0
» Views: 217
PD50SNE-G clevo bios unlock request
Last Post: secretciph3r
08-23-2026 06:04 AM
» Replies: 0
» Views: 265
[Request] Dell 7559 bios fully unlocked
Last Post: RedDeam
08-21-2026 02:20 PM
» Replies: 26
» Views: 33195
Core2Extreme X9000 running amazing on an...
Last Post: Hin
08-21-2026 05:45 AM
» Replies: 2
» Views: 3514
Looking for virgin/clean dev BIOS for HP...
Last Post: Smarty
08-21-2026 04:08 AM
» Replies: 0
» Views: 301
[REQUEST] Lenovo G500 (78CNxxWW) Whiteli...
Last Post: steven1801_
08-21-2026 03:29 AM
» Replies: 1234
» Views: 674126
[REQUEST] Lenovo Ideapad Gaming 3-15ACH6...
Last Post: openg664
08-19-2026 05:35 AM
» Replies: 7
» Views: 9851
[SOLVED] Lenovo E545 (HRETxxWW) WiFi + B...
Last Post: Dudu2002
08-17-2026 01:12 PM
» Replies: 270
» Views: 171279
AMI BIOS modding nvme-boot
Last Post: marktuan
08-17-2026 07:12 AM
» Replies: 1
» Views: 3409
Dell Precision 3490 qwery about dell eps...
Last Post: krzysztoft1
08-17-2026 05:03 AM
» Replies: 0
» Views: 469
Bloqueo de bios de Acer aspire 5 15 a515...
Last Post: Emewhi
08-16-2026 12:52 PM
» Replies: 0
» Views: 462
[REQUEST] HP Pavilion dv6-3110ST (XR556E...
Last Post: AhmetBaki
08-15-2026 06:27 PM
» Replies: 0
» Views: 521
Asus Prime Q370M-C: Remove The Password
Last Post: DeathBringer
08-15-2026 11:29 AM
» Replies: 2
» Views: 2144
[REQUEST] Lenovo ThinkCentre M93p Tiny (...
Last Post: Route66Fan
08-15-2026 03:31 AM
» Replies: 58
» Views: 71744
[REQUEST] Lenovo G700 (7ACNxxWW) Whiteli...
Last Post: ManulSibirskiy
08-14-2026 06:22 PM
» Replies: 168
» Views: 120769

[REQUEST] AMI Aptio BIOS password Advantech UNO-1372G-J (UNOB-2117MB)
#1
Hello everyone,

I'm stuck on a BIOS password issue on an industrial embedded PC and would really appreciate some expert eyes on this. I've done what I can with hex editing but I think the real password check is elsewhere in the firmware, beyond my current skill level.

Hardware:

Device: Advantech UNO-1372G-J (industrial fanless PC / OPC)
Motherboard: UNOB-2117MB REV.A1, made in Taiwan, PN 19A3211703-01
CPU: Intel (embedded SoC, soldered)
Main BIOS flash chip: Winbond W25Q64JW (8MB, SOIC-8, 1.8V)

Problem:
The BIOS requires a password at boot/setup entry. Clearing CMOS (battery pull + CN36 clear-CMOS jumper + shorting battery socket V+/V-) has no effect on the password — as expected, since on these AMI Aptio boards it's stored in SPI flash rather than battery-backed CMOS.

What I've tried so far:


Dumped the main BIOS chip (W25Q64JW) via CH341A + 1.8V adapter + SOIC-8 clip. Read 3 times, MD5-verified identical each time.
Located what appears to be the AMI TSE (Total Setup Edition) password-related NVAR variables in the dump:

AMITSESetup NVAR entry (offset ~0x300281) with all-zero data (looks like a "default/empty" instance)
A second AMITSESetup NVAR entry (offset ~0x302931, size 0x68) containing non-zero data — what I assumed to be password hash material (80 bytes, structured as two overlapping ~40-byte sequences)
An OEMDEFAULTPWDSetup NVAR entry (offset ~0x302999) with a single data byte (0x04, later noticed value 0x70 depending on offset interpretation — I may have made an error here)

Tried zeroing the 64 then 80 bytes of the suspected hash data in the second AMITSESetup NVAR — reflashed, no change, password still requested.
Tried invalidating the NVAR entries entirely by changing the state byte from FF FF FF to 3C FF FF on both AMITSESetup and OEMDEFAULTPWDSetup entries — reflashed, verified the re-dump matched the written image exactly (MD5 identical), so the write itself succeeded with no write-protection issue — but the password prompt is still there.

So the chip write/erase/verify cycle works fine (no WP/lock issue), but neither approach neutralizes the actual password check. My guess is either:

The AMITSESetup varstore I found is just the general Setup form storage (all BIOS settings), not specifically the password, and the real password hash is stored/checked elsewhere (different GUID, different NVAR name, or computed by DXE/PEI driver code rather than a plain stored hash)
There's some checksum/CRC over the NVRAM volume that needs to be recalculated after modification, and an invalid checksum causes the driver to fall back to a "locked" state rather than "no password"

What I'm hoping for:


Guidance on identifying the correct NVAR GUID/variable that AMI Aptio uses for password verification, as opposed to general Setup storage
Whether AMIBCP (AMI BIOS Configuration Program) can open/patch this dump properly, since UEFITool NE reports "Stores not found" on this image
Any known quirks specific to Advantech's AMI Aptio implementation


I have the original untouched dump and full change logs for every attempt. Happy to upload the original .bin if that helps, and I can provide any additional dumps/photos of the board on request.

Thanks in advance for any pointers!
find
quote


Forum Jump:


Users browsing this thread: 1 Guest(s)