Skip to content

Latest commit

 

History

4 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

H298A V1.0 Config Tool

A small Python tool for decrypting, editing, and rebuilding config.bin backups from ZTE ZXHN H298A V1.0.

This is a continuation of the root-enabler work for the same router. After getting root access and tracing the firmware, I reversed the working backup format enough to support a full offline decode/edit/encode workflow.

Tested on firmware/build:

  • TTN.26_240416

What this does

  • Decrypts config.bin to XML
  • Rebuilds config.bin from edited XML
  • Supports fetching the device-specific MD5 directly from the router over SSH/CLI
  • Produces a byte-identical round-trip for an untouched original backup
  • Produces modified backups that can be re-uploaded successfully

Requirements

Install dependencies:

pip install pycryptodome pexpect

If you do not use --router, pexpect is not required.

Usage

Decode a backup:

python3 h298a_config_tool.py decode --md5 <md5> config.bin

Rebuild a backup after editing the XML:

python3 h298a_config_tool.py encode --md5 <md5> config.bin.xml

Or let the tool fetch the MD5 from the router directly:

python3 h298a_config_tool.py decode --router config.bin
python3 h298a_config_tool.py encode --router config.bin.xml

The tool writes:

  • config.bin.xml after decode
  • reencrypted.config.bin after encode

Getting the MD5

The tool needs the MD5 of the router's tag partition.

Run this on the router to get it manually:

openssl dgst -md5 /dev/mtd2

Example output:

MD5(/dev/mtd2)= <md5>

Use the hash value:

python3 h298a_config_tool.py decode --md5 <md5> config.bin

Router mode

If the router is already rooted and SSH is available, the tool can fetch the MD5 automatically:

python3 h298a_config_tool.py decode --router config.bin

It will prompt for:

  • router IP
  • SSH username/password
  • shell username/password

This mode supports both SSH flows that are observed on the H298A:

  1. SSH password -> CLI> -> shell -> BusyBox login
  2. SSH password -> direct BusyBox Login: / Password: prompt

If the SSH flow does not match either of these, or SSH is not enabled, use --md5 manually instead.

Typical workflow

  1. Download config.bin from the router web UI
  2. Get the router MD5 using openssl dgst -md5 /dev/mtd2 or just let the tool fetch it with --router
  3. Decode:
python3 h298a_config_tool.py decode --md5 <md5> config.bin
  1. Edit config.bin.xml
  2. Rebuild:
python3 h298a_config_tool.py encode --md5 <md5> config.bin.xml
  1. Upload reencrypted.config.bin back to the router

How it works

The tool implements the runtime path actually used by this router for config backup import/export.

The important points are:

  • config.bin is base64-wrapped
  • after base64 decoding, the first 0x1b bytes are an outer wrapper
  • the inner payload is an AES-CBC chunked container
  • the decrypted output is another chunked container holding zlib-compressed chunks
  • the actual device-specific key source used at runtime is:
MD5(/dev/mtd2)

That MD5 is then used as the input to the final AES derivation:

  • AES key = SHA256(md5_blob)
  • AES IV = first 16 bytes of SHA256(md5_blob)

Both encrypted and compressed containers use:

  • 60-byte headers
  • 12-byte chunk headers
  • big-endian fields

Notes

  • This tool was built from reversing the H298A V1.0 firmware path
  • The firmware still contains the older dbcSetEncryKey() path using hidden tag 0x1004, but for this product build the runtime export/import buffers are later overwritten by product-specific logic based on MD5(/dev/mtd2)
  • The untouched original config.bin reamains byte-identically through this tool

Related project

If you need root access first, use the root-enabler project for the same router:

This config tool assumes you either already have a backup file and MD5, or already have root access.

Safety

  • Always keep the original config.bin untouched
  • Test with a small change first
  • Use only on hardware and networks you own or are authorized to test

About

A small Python tool for decrypting, editing, and rebuilding config.bin backups from ZTE ZXHN H298A V1.0

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages