[Q] Hisense U8G Root (MT5895)

Search This thread

iwasaperson

Senior Member
Aug 31, 2010
339
110
Hello. I have unlocked the bootloader of my Hisense U8G TV running M0422 firmware, but I can't figure out any way to dump boot.img so I can root, or get into BROM mode to use mtkclient (MT5895).

I have a firmware package file, but it's encrypted and the keys are not publicly available (I tried epk2extract already). It's in a mediatek pkg format.

I can't access any of /dev/block/* or /dev/mmcblk0* without root. I need to dump mmcblk0p14 (boot_a) and mmcblk0p53 (boot_b)

Anyone have ideas? Software is too new for any temp root exploits, unfortunately. Android 10 patch level Feb 2022. mtk-su doesn't work. KingoRoot doesn't work, etc.

Basically I need any of the following:
BROM access without having to open up the TV (I've tried several methods, including shorting USB Data+ to GND, holding power (the only button on this TV) while turning on, just plugging it in and running lsusb, Holding several remote buttons while plugging in (Holding remote power button while plugging in will take you to firmware updater if fw file is detected)
Being able to decrypt and extract the firmware package
Any other way of getting a boot.img dump. Once I have root, I can dump everything else.
 

codernixx

New member
Dec 4, 2022
3
1
Hello. I have unlocked the bootloader of my Hisense U8G TV running M0422 firmware, but I can't figure out any way to dump boot.img so I can root, or get into BROM mode to use mtkclient (MT5895).

I have a firmware package file, but it's encrypted and the keys are not publicly available (I tried epk2extract already). It's in a mediatek pkg format.

I can't access any of /dev/block/* or /dev/mmcblk0* without root. I need to dump mmcblk0p14 (boot_a) and mmcblk0p53 (boot_b)

Anyone have ideas? Software is too new for any temp root exploits, unfortunately. Android 10 patch level Feb 2022. mtk-su doesn't work. KingoRoot doesn't work, etc.

Basically I need any of the following:
BROM access without having to open up the TV (I've tried several methods, including shorting USB Data+ to GND, holding power (the only button on this TV) while turning on, just plugging it in and running lsusb, Holding several remote buttons while plugging in (Holding remote power button while plugging in will take you to firmware updater if fw file is detected)
Being able to decrypt and extract the firmware package
Any other way of getting a boot.img dump. Once I have root, I can dump everything else.
Bro,I have a rom of hisense tv, Can you extract the boot image for me,plz?
 
  • Like
Reactions: chris1892006

Top Liked Posts

  • There are no posts matching your filters.
  • 1
    Hello. I have unlocked the bootloader of my Hisense U8G TV running M0422 firmware, but I can't figure out any way to dump boot.img so I can root, or get into BROM mode to use mtkclient (MT5895).

    I have a firmware package file, but it's encrypted and the keys are not publicly available (I tried epk2extract already). It's in a mediatek pkg format.

    I can't access any of /dev/block/* or /dev/mmcblk0* without root. I need to dump mmcblk0p14 (boot_a) and mmcblk0p53 (boot_b)

    Anyone have ideas? Software is too new for any temp root exploits, unfortunately. Android 10 patch level Feb 2022. mtk-su doesn't work. KingoRoot doesn't work, etc.

    Basically I need any of the following:
    BROM access without having to open up the TV (I've tried several methods, including shorting USB Data+ to GND, holding power (the only button on this TV) while turning on, just plugging it in and running lsusb, Holding several remote buttons while plugging in (Holding remote power button while plugging in will take you to firmware updater if fw file is detected)
    Being able to decrypt and extract the firmware package
    Any other way of getting a boot.img dump. Once I have root, I can dump everything else.
    Bro,I have a rom of hisense tv, Can you extract the boot image for me,plz?