Home Forum Blog Private Support Courses
Our courses are now on YouTube! Start Watching
Hovatek Forum OPERATING SYSTEMS Android [Tutorial] How to unlock Unisoc (SPD) bootloader using Identifier Token

[Tutorial] How to unlock Unisoc (SPD) bootloader using Identifier Token

[Tutorial] How to unlock Unisoc (SPD) bootloader using Identifier Token

Pages (42): Previous 1 38 39 40 41 42 Next
mpm86
mpm86
mpm86
Enthusiastic Member
5
19-09-2025, 04:08 AM



Will this work on device that has only two physical buttons? Power on the side and reset on the back. It's android portable head unit screen, bought on aliexpress, seller "imagebon", model name "W60N". If it won't work, is there other way to unlock bootloader, root etc? All I want to do so far is to change ugly boot animation...
hovatek
hovatek
hovatek
Administrator
50,891
27-09-2025, 07:15 AM
(19-09-2025, 04:08 AM)mpm86 Will this work on device that has only two physical buttons? Power on the side and reset on the back. It's android portable head unit screen, bought on aliexpress, seller "imagebon", model name "W60N". If it won't work, is there other way to unlock bootloader, root etc? All I want to do so far is to change ugly boot animation...

One of them might work for the bootloader unlock process. Also, depending on the key used to sign the partitions, it might be possible to gain root without unlocking the bootloader. Then using a magisk module to change boot animation

Learn MediaTek, Unisoc / Spreadtrum (SPD) and Qualcomm Software Repairs @ https://www.hovatek.com/training
Note!
We have a reply schedule for Forum Support. Please try Private Support if you can't wait.
mpm86
mpm86
mpm86
Enthusiastic Member
5
27-09-2025, 08:18 PM
Thank you for your reply. So far I found FW contact pad on the PCB, shorted to GND while plugging USB cable makes it enter download mode, but only for about 5 seconds. It's recognised in my laptop, correct drivers are installed. I was able to grab OTA update file and extract it. When plugged it with Research Download Tool, with only fdl1 and fdl2 (extracted from .pac firmware for Teclast T45HD - the same chipset), whilst shorting FW to GND, device is detected brielfy, then it reboots to android, Research Download then shows:
STEP: FDL, STATUS: UNPLUGGED, PROGRESS: FAILED: [PS2262] USER CANCEL.
Also unsuccessful with handshake in Cheetah Tool Pro.
What else can I try?
Gargoyle
Gargoyle
Gargoyle
Contributor
577
27-09-2025, 08:46 PM
(27-09-2025, 08:18 PM)mpm86 Thank you for your reply. So far I found FW contact pad on the PCB, shorted to GND while plugging USB cable makes it enter download mode, but only for about 5 seconds. It's recognised in my laptop, correct drivers are installed. I was able to grab OTA update file and extract it. When plugged it with Research Download Tool, with only fdl1 and fdl2 (extracted from .pac firmware for Teclast T45HD - the same chipset), whilst shorting FW to GND, device is detected brielfy, then it reboots to android, Research Download then shows:
STEP: FDL, STATUS: UNPLUGGED, PROGRESS: FAILED: [PS2262] USER CANCEL.
Also unsuccessful with handshake in Cheetah Tool Pro.
What else can I try?

[Image: 2025-09-27-21-43-31.jpg]
But that one button has two functions: volume up and volume down.
Start the flashing process using the Research Download Tool, connect the powered-off device with a USB cable while holding down the volume down button.

If it's a newer model, this method probably won't work.
What is the exact model number?
This post was last modified: 27-09-2025, 09:04 PM by Gargoyle.
mpm86
mpm86
mpm86
Enthusiastic Member
5
27-09-2025, 09:15 PM

Mediatek Course Mediatek Course


Thanks for reply @Gargoyle, it's portable android car screen, model name listed by manufacturer is W60N, seller on aliexpress. I doesn't have volume buttons, only floating on screen button, which opens volume control/screen brightness/home button... I found contact pad (FW) which when shorted to GND while plugging USB makes it enter download mode briefly, my laptop detects it as SPRD U2S DIAG (COM6). I can't see any other contact pads that could also be used. There's also pinhole button on the back (reset). I suppose that because FDL1 and FDL2 I used from .pac for Teclast T45HD (the same chipset UMS9230) are signed for Teclast, the seller won't send me .pac firmware, I only have OTA downloaded. SPD tools and Cheetah Tool Pro appear not being able to handshake with BROM due to missing signed FDL1/2.
Gargoyle
Gargoyle
Gargoyle
Contributor
577
28-09-2025, 09:33 AM
That's a good point, my mistake. I was confused by the mention of the Teclast T45HD.

Ah, so it's likely an issue with FDL1 and FDL2.
I'm afraid you won't find the firmware easily.
This post was last modified: 28-09-2025, 09:49 AM by Gargoyle.
mpm86
mpm86
mpm86
Enthusiastic Member
5
05-10-2025, 09:23 PM
I'm curious to try this method:

exec_addr [addr]
(brom stage only)
Sends custom_exec_no_verify_addr.bin to the specified memory address to bypass the signature verification by brom for splloader/fdl1.
Used for CVE-2022-38694

I have pac firmware for different device, but the same chipset, so I have fdl's but signed for different device... If this can bypass signature verification, then it would be 1 step forward, in my case...
kaka1a
kaka1a
kaka1a
Techie Member
51
29-11-2025, 01:30 AM
(12-02-2020, 06:25 PM)hovatek after issuing the command , linux shell scr was accurately converted to powershell scr,
...
This post was last modified: 03-12-2025, 09:49 AM by hovatek.
11-02-2026, 04:26 PM
(bootloader) Identifier token:

(bootloader) 413354623831323830303033323935

OKAY [ 0.001s]
finished. total time: 0.001s
root@ubuntu:/home/ubuntu/Desktop/modified_fastboot# ./signidentifier_unlockbootloader.sh 413354623831323830303033323935 rsa4096_vbmeta.pem signature.bin
-bash: ./signidentifier_unlockbootloader.sh: Permission denied
root@ubuntu:/home/ubuntu/Desktop/modified_fastboot#

Hello. I can't go any further. What should I do? Thank you.
11-02-2026, 04:28 PM
(bootloader) Identifier token:

(bootloader) 413354623831323830303033323935

OKAY [ 0.001s]
finished. total time: 0.001s
root@ubuntu:/home/ubuntu/Desktop/modified_fastboot# ./signidentifier_unlockbootloader.sh 413354623831323830303033323935 rsa4096_vbmeta.pem signature.bin
-bash: ./signidentifier_unlockbootloader.sh: Permission denied
root@ubuntu:/home/ubuntu/Desktop/modified_fastboot#

Hello. I can't go any further. What should I do? Thank you.
umidigi a13 tab
Pages (42): Previous 1 38 39 40 41 42 Next
Users browsing this thread:
 10 Guest(s)
Users browsing this thread:
 10 Guest(s)
WhTlYt