Bricked R8000

Bricked R8000

Hey All,

New hear hoping someone has the answer.

Flashed initial tomato to stock firmware on my netgear R8000.

Then upgraded to latest Arm-137 AIO . RIght after that stuck in boot loop.

Tried multiple resets does no luck.

Started continuous ping.. After 15seconds I get 4 pings from router and then nothing.

Hook up my usb-ttl. Can see boot sequence but cant break boot with Ctrl+C .

Tried many times and nothing. Tried with flow control on and off.

Do I have a new door stop?

Or does anyone know a way around this?


Thanks guys

I'm sorry but I have a hard

I'm sorry but I have a hard time following what you're saying. Can you explain in proper English, please? The flashing process is a very delicate procedure so we need to know the exact steps done, preferably in proper English

Thanks for replying microchip

I have an R8000 that when powered on has amber power light.

If I set a constant ping to it, I will get a total of 4 TTL=100 back but thats it.

I have tried tftp an image file to it via windows, and I have also tried using usb-ttl adapter.

When using the serial connection I see the boot sequence, I keep hitting CTRL-C but never get the CFE prompt.

Is there any other process anyone knows about to de-brick?

Below is also the out put

I have been hammering ctrl-c from instant it turns on until reboot with no luck getting the CFE prompt.




Digital core power voltage set to 1.0V




RDLYW0 00000004

RDENW0 00000034


 00 ---------+++++++++++++++++++++++X+++++++++++++++++++++++--------
 01 --------------++++++++++++++++++++++X+++++++++++++++++++++------
 02 ---------+++++++++++++++++++++++X+++++++++++++++++++++++--------
 03 --------+++++++++++++++++++++++X++++++++++++++++++++++----------
 04 ----++++++++++++++++++++++X++++++++++++++++++++++---------------
 05 ----------+++++++++++++++++++++++X+++++++++++++++++++++++-------
 06 ------++++++++++++++++++++++X+++++++++++++++++++++--------------
 07 ------------++++++++++++++++++++++X++++++++++++++++++++++-------
 08 ------++++++++++++++++++++++X++++++++++++++++++++++-------------
 09 -----------++++++++++++++++++++++++X++++++++++++++++++++++++----
 10 -------+++++++++++++++++++++++X++++++++++++++++++++++-----------
 11 -------------+++++++++++++++++++++++X++++++++++++++++++++++-----
 12 -----+++++++++++++++++++++++X+++++++++++++++++++++++------------
 13 ------------++++++++++++++++++++++X++++++++++++++++++++++-------
 14 --------+++++++++++++++++++++++X+++++++++++++++++++++++---------
 15 ------------+++++++++++++++++++++++X++++++++++++++++++++++------


 00 ++++++++++++++++++++++++++++X+++++++++++++++++++++++++++--------
 01 ---+++++++++++++++++++++++++++X+++++++++++++++++++++++++++------
 02 ++++++++++++++++++++++++++++X+++++++++++++++++++++++++++--------
 03 +++++++++++++++++++++++++++X++++++++++++++++++++++++++----------
 04 ++++++++++++++++++++++++X++++++++++++++++++++++++---------------
 05 ++++++++++++++++++++++++++++X++++++++++++++++++++++++++++-------
 06 +++++++++++++++++++++++++X++++++++++++++++++++++++--------------
 07 --+++++++++++++++++++++++++++X+++++++++++++++++++++++++++-------
 08 +++++++++++++++++++++++++++X++++++++++++++++++++++++++----------
 09 ----++++++++++++++++++++++++++++X++++++++++++++++++++++++++++---
 10 +++++++++++++++++++++++++++X+++++++++++++++++++++++++++---------
 11 ----++++++++++++++++++++++++++++X++++++++++++++++++++++++++++---
 12 +++++++++++++++++++++++++++X++++++++++++++++++++++++++----------
 13 -----++++++++++++++++++++++++++X++++++++++++++++++++++++++------
 14 ++++++++++++++++++++++++++++X++++++++++++++++++++++++++++-------
 15 ---++++++++++++++++++++++++++++X+++++++++++++++++++++++++++-----


 00 --------++++++++++++++++++++++++X+++++++++++++++++++++++--------
 01 -------------++++++++++++++++++++++++X+++++++++++++++++++++++---
 02 ----------+++++++++++++++++++++++X+++++++++++++++++++++++-------
 03 --------+++++++++++++++++++++++X+++++++++++++++++++++++---------
 04 ----+++++++++++++++++++++++X+++++++++++++++++++++++-------------
 05 ----------++++++++++++++++++++++++X++++++++++++++++++++++++-----
 06 ------++++++++++++++++++++++X++++++++++++++++++++++-------------
 07 ------------++++++++++++++++++++++++X++++++++++++++++++++++++---
 08 ------++++++++++++++++++++++X+++++++++++++++++++++--------------
 09 -----------++++++++++++++++++++++++X++++++++++++++++++++++++----
 10 -------+++++++++++++++++++++++X++++++++++++++++++++++-----------
 11 -------------+++++++++++++++++++++++X++++++++++++++++++++++-----
 12 -----++++++++++++++++++++++++X+++++++++++++++++++++++-----------
 13 ------------++++++++++++++++++++++X++++++++++++++++++++++-------
 14 --------+++++++++++++++++++++++X+++++++++++++++++++++++---------
 15 -----------+++++++++++++++++++++++X+++++++++++++++++++++++------


 00 +++++++++++++++++++++++X+++++++++++++++++++++++--------++++++++-
 01 ++++++++++++++++++++++++X++++++++++++++++++++++++-------+++++++-
 02 +++++++++++++++++++++++X+++++++++++++++++++++++-------+++++++++-
 03 +++++++++++++++++++++++X++++++++++++++++++++++--------+++++++++-
 04 +++++++++++++++++++++X++++++++++++++++++++-----------++++++++++-
 05 ++++++++++++++++++++++++X+++++++++++++++++++++++-------++++++++-
 06 +++++++++++++++++++++X+++++++++++++++++++++----------++++++++++-
 07 ++++++++++++++++++++++++X+++++++++++++++++++++++-------++++++++-
 08 +++++++++++++++++++++++X++++++++++++++++++++++---------++++++++-
 09 -+++++++++++++++++++++++X+++++++++++++++++++++++-----------++++-
 10 +++++++++++++++++++++++X+++++++++++++++++++++++---------+++++++-
 11 ---++++++++++++++++++++++X++++++++++++++++++++++-------------++-
 12 ++++++++++++++++++++++++X+++++++++++++++++++++++-------++++++++-
 13 --+++++++++++++++++++++++X+++++++++++++++++++++++-----------+++-
 14 ++++++++++++++++++++++++X+++++++++++++++++++++++---------++++++-
 15 --+++++++++++++++++++++++X++++++++++++++++++++++------------+++-

WRDMW0 00000022
WRDMW0 00000024


 00 +++++++++++++++++++S+++++++++++X++++++++++++++++++++++++++++++++


CFE for Foxconn Router R8000 version: v1.0.8
Build Date: Fri May 30 15:03:06 CST 2014
Init Arena
Init Devs.
Boot up from NAND flash...
Bootcode Boot partition size = 524288(0x80000)
DDR Clock: 800 MHz
Info: DDR frequency set from clkfreq=1000,*800*
et2: Broadcom BCM47XX 10/100/1000 Mbps Ethernet Controller (r474543)
CPU type 0x0: 1000MHz
Tot mem: 262144 KBytes

Device eth0:  hwaddr E8-FC-AF-F9-69-A8, ipaddr, mask
        gateway not set, nameserver not set
Checking crc...Loader:raw Filesys:raw Dev:nflash0.os File: Options:(null)
Loading: .... 4304128 bytes read
Entry at 0x00008000
Closing network.
Starting program at 0x00008000
console [ttyS0] enabled, bootconsole disabled
serial8250.0: ttyS1 at MMIO 0x18000400 (irq = 117) is a 16550
brd: module loaded
loop: module loaded
pflash: found no supported devices
bcmsflash: found no supported devices
Boot partition size = 524288(0x80000)
lookup_nflash_rootfs_offset: offset = 0x200000
nflash: squash filesystem with lzma found at block 29
Creating 5 MTD partitions on "nflash":
0x000000000000-0x000000080000 : "boot"
0x000000080000-0x000000200000 : "nvram"
0x000000200000-0x000004200000 : "linux"
0x0000003b4d28-0x000004000000 : "rootfs"
0x000002200000-0x000002240000 : "board_data"
PPP generic driver version 2.4.2
PPP MPPE Compression module registered
NET: Registered protocol family 24
PPTP driver version 0.8.5
=== PPTP init ===
u32 classifier
    Actions configured
Netfilter messages via NETLINK v0.30.
nf_conntrack version 0.5.0 (3989 buckets, 15956 max)
ctnetlink v0.93: registering with nfnetlink.
xt_time: kernel timezone is -0000
ip_tables: (C) 2000-2006 Netfilter Core Team
TCP cubic registered
NET: Registered protocol family 10
ip6_tables: (C) 2000-2006 Netfilter Core Team
NET: Registered protocol family 17
L2TP core driver, V2.0
PPPoL2TP kernel driver, V2.0
802.1Q VLAN Support v1.8 Ben Greear <[email protected]>
All bugs added by David S. Miller <[email protected]>
Registering the dns_resolver key type
Northstar brcmnand NAND Flash Controller driver, Version 0.1 (c) Broadcom Inc. 2012
NAND device: Manufacturer ID: 0x01, Chip ID: 0xf1 (AMD NAND 128MiB 3,3V 8-bit)
Spare area=64 eccbytes 56, ecc bytes located at:
 2 3 4 5 6 7 8 9 10 11 12 13 14 15 18 19 20 21 22 23 24 25 26 27 28 29 30 31 34 35 36 37 38 39 40 41 42 43 44 45 46 47 50 51 52 53 54 55 56 57 58 59 60 61 62 63
Available 7 bytes at (off,len):
(1,1) (16,2) (32,2) (48,2) (0,0) (0,0) (0,0) (0,0)
Scanning device for bad blocks
Creating 1 MTD partitions on "brcmnand":
0x000004000000-0x000008000000 : "brcmnand"
VFS: Mounted root (squashfs filesystem) readonly on device 31:3.
devtmpfs: mounted
Freeing init memory: 216K

Hit ENTER for console...

ctf: module license 'Proprietary' taints kernel.
Disabling lock debugging due to kernel taint
et_module_init: passivemode set to 0x0
et_module_init: txworkq set to 0x0
et_module_init: et_txq_thresh set to 0x400
et_module_init: et_rxlazy_timeout set to 0x3e8
et_module_init: et_rxlazy_framecnt set to 0x20
fwd0: Broadcom BCM47XX 10/100/1000 Mbps Ethernet Controller (r527781)
fwd1: Broadcom BCM47XX 10/100/1000 Mbps Ethernet Controller (r527781)
eth0: Broadcom BCM47XX 10/100/1000 Mbps Ethernet Controller (r527781)
dhd_module_init in
dhd_queue_budget = 256
dhd_sta_threshold = 2048
no wifi platform data, skip
PCI_PROBE:  bus 1, slot 0,vendor 14E4, device AA52(good PCI location)
PCI: Enabling device 0001:01:00.0 (0140 -> 0142)
DHD: dongle ram size is set to 983040(orig 983040) at 0x180000
dhd_attach(): thread:dhd_watchdog_thread:2f6 started
dhd_deferred_work_init: work queue initialized
Dongle Host Driver, version 1.194.33 (r526004)
Compiled in drivers/net/wireless/bcmdhd on Jun 17 2015 at 11:27:36
Register interface [eth1]  MAC: 00:90:4c:11:22:33

dhdpcie_download_code_array: Download, Upload and compare succeeded (43602a1-roml/pcie-ag-splitrx-fdap-mbss-mfp-wl11k-wl11u-txbf-pktctx-amsdutx-ampduretry-chkd2hdma-proptxstatus, 2015.06.17.111523, 2015/06/17 11:15:23).
dhdpcie_bus_write_vars: Download, Upload and compare of NVRAM succeeded.
dhdpcie_readshared: address (0xfe1a01e5) of pciedev_shared invalid
Waited 5006383 usec, dongle is not ready
dhd_bus_init :Shared area read failed
dhd_bus_start, dhd_bus_init failed -1
dhdpcie_init: dhd_bud_start() failed
dhdpcie_readshared: address (0xfe1a01e5) of pciedev_shared invalid
Waited 5006383 usec, dongle is not ready
Enforcing kernel panic
Unable to handle kernel NULL pointer dereference at virtual address 00000000
pgd = c0004000
[00000000] *pgd=00000000
Internal error: Oops: 817 [#1] PREEMPT SMP
last sysfs file: /sys/kernel/uevent_seqnum
module:  dhd     bf02e000        799274
module:  et      bf01b000        48925
module:  igs     bf013000        11927
module:  emf     bf00a000        15169
module:  ctf     bf000000        16424
Modules linked in: dhd(+) et(P) igs(P) emf(P) ctf(P)
CPU: 1    Tainted: P             ( #3)
PC is at dhdpcie_bus_process_mailbox_intr+0x15c/0x1e8 [dhd]
LR is at dhdpcie_bus_process_mailbox_intr+0x17c/0x1e8 [dhd]
pc : [<bf041440>]    lr : [<bf041460>]    psr: 20000113
sp : cf83ded0  ip : c044aee4  fp : 00000000
r10: c003c1d4  r9 : c0450f20  r8 : c0455cd8
r7 : bf05cd00  r6 : 00000000  r5 : 00000100  r4 : cf9d3000
r3 : 00000000  r2 : cf83c000  r1 : 60000113  r0 : 00000019
Flags: nzCv  IRQs on  FIQs on  Mode SVC_32  ISA ARM  Segment kernel
Control: 10c53c7d  Table: 8fb8004a  DAC: 00000017
Process swapper (pid: 0, stack limit = 0xcf83c270)
Stack: (0xcf83ded0 to 0xcf83e000)
dec0:                                     00000000 cf9d3000 00000000 b83ef180
dee0: cf83c000 cf9d3000 00000100 00000000 cf83c000 bf051d08 00000100 bf05cd00
df00: ce680000 ce683898 00000000 bf03324c ce683894 c006955c c0069450 00000001
df20: c0400058 cf83c000 00000103 c003c148 c0400040 c0450f20 00000001 c03c1330
df40: d0810000 c0057c94 00000006 0000000a 00000008 cf83c000 c0455cd8 c003c9d0
df60: cf83c000 00000000 cf83c000 0000001f 00000000 c0069d00 000000a3 c03c0ec0
df80: ffffffff f0100100 000000a3 00000002 00000001 c03c09e8 00000002 cf922d00
dfa0: cf83dfe0 00000000 cf83c000 c04230a8 c040ab80 c0423214 80000000 413fc090
dfc0: 0000001f 00000000 00000000 cf83dfe0 c003fbe4 c003fbe8 60000013 ffffffff
dfe0: c003fbc4 c003fd88 8f84806a 0000001f 10c03c7d 80008148 ed57ffef ffffffff
[<bf041440>] (PC is at dhdpcie_bus_process_mailbox_intr+0x15c/0x1e8 [dhd])
[<bf041440>] (dhdpcie_bus_process_mailbox_intr+0x15c/0x1e8 [dhd]) from [<bf051d08>] (dhd_bus_dpc+0xc8/0x150 [dhd])
unwind: Index not found bf051d08
Code: e5973000 e3130001 1a000006 e3a03000 (e5833000)
---[ end trace 42161ca811e67e97 ]---
Kernel panic - not syncing: Fatal exception in interrupt
[<c0044ff8>] (unwind_backtrace+0x0/0xf8) from [<c02f979c>] (panic+0x7c/0x1a8)
[<c02f979c>] (panic+0x7c/0x1a8) from [<c00426f8>] (die+0x1ac/0x1dc)
[<c00426f8>] (die+0x1ac/0x1dc) from [<c0046390>] (__do_kernel_fault+0x6c/0x8c)
[<c0046390>] (__do_kernel_fault+0x6c/0x8c) from [<c0046500>] (do_page_fault+0x150/0x1ec)
[<c0046500>] (do_page_fault+0x150/0x1ec) from [<c003e3a4>] (do_DataAbort+0x30/0x9c)
[<c003e3a4>] (do_DataAbort+0x30/0x9c) from [<c03c098c>] (__dabt_svc+0x4c/0x60)
Exception stack(0xcf83de88 to 0xcf83ded0)
de80:                   00000019 60000113 cf83c000 00000000 cf9d3000 00000100
dea0: 00000000 bf05cd00 c0455cd8 c0450f20 c003c1d4 00000000 c044aee4 cf83ded0
dec0: bf041460 bf041440 20000113 ffffffff
[<c03c098c>] (__dabt_svc+0x4c/0x60) from [<bf041440>] (dhdpcie_bus_process_mailbox_intr+0x15c/0x1e8 [dhd])
[<bf041440>] (dhdpcie_bus_process_mailbox_intr+0x15c/0x1e8 [dhd]) from [<bf051d08>] (dhd_bus_dpc+0xc8/0x150 [dhd])
unwind: Index not found bf051d08
CPU0: stopping
Rebooting in 3 seconds..[<c0044ff8>] (unwind_backtrace+0x0/0xf8) from [<c003e334>] (do_IPI+0x114/0x154)
[<c003e334>] (do_IPI+0x114/0x154) from [<c03c09e8>] (__irq_svc+0x48/0xe8)
Exception stack(0xc03fff78 to 0xc03fffc0)
ff60:                                                       c8207020 cf9e3600
ff80: c03fffc0 00000000 c03fe000 c04230a8 c040ab80 c040ab78 80000000 413fc090
ffa0: 0000001f 00000000 00000000 c03fffc0 c003fbe4 c003fbe8 60000013 ffffffff
[<c03c09e8>] (__irq_svc+0x48/0xe8) from [<c003fbe8>] (default_idle+0x24/0x28)
[<c003fbe8>] (default_idle+0x24/0x28) from [<c003fd88>] (cpu_idle+0x70/0xa4)
[<c003fd88>] (cpu_idle+0x70/0xa4) from [<c0008e8c>] (start_kernel+0x3cc/0x42c)
[<c0008e8c>] (start_kernel+0x3cc/0x42c) from [<80008148>] (0x80008148)

Just a shot in the dark, but

Just a shot in the dark, but have you tried pressing "enter"?

" devtmpfs: mounted

Freeing init memory: 216K

Hit ENTER for console...

ctf: module license 'Proprietary' taints kernel.
Disabling lock debugging due to kernel taint "

lol ^