Dual Band (concurrent), Gigabit Ethernet and ADSL Modem. Advertised as 1750 Mbps. It has simultaneous Triple-Stream (3×3) radios on both 2.4GHz and 5 GHz Bands. It supports 802.11n in 2.4GHz for 450Mbps throughput and IEEE 802.11ac (draft) for 1300Mbps throughput in 5GHz.
This modem is practically divided in 2 sections:
→ Install OpenWrt (generic explanation)
The following instructions require a connection to the J1 UART header and are tested for the Archer D7 v1. For the Archer D7b v1, names should be changed accordingly.
tpl to stop autobooting and obtain U-Boot CLI access.tftpboot 0x81000000 openwrt-ath79-generic-tplink_archer-d7-v1-squashfs-sysupgrade.bin erase 0x9f020000 +f90000 cp.b 0x81000000 0x9f020000 0xf90000 reset
tpl to stop autobooting and obtain U-Boot CLI access.tftpboot 0x81000000 openwrt-ath79-generic-tplink_archer-d7-v1-initramfs-kernel.bin bootm 0x81000000
dd if="Archer_D7v1_1.6.0_0.9.1_up_boot(160216)_2016-02-16_15.55.48.bin" of="Archer_D7v1_1.6.0_0.9.1_up_boot(160216)_2016-02-16_15.55.48.bin.mod" skip=257 bs=512 count=31872
tftpboot 0x81000000 Archer_D7v1_1.6.0_0.9.1_up_boot(160216)_2016-02-16_15.55.48.bin.mod erase 0x9f020000 +f90000 cp.b 0x81000000 0x9f020000 0xf90000 reset
| Architecture | MIPS32 (MIPS74Kc) |
|---|---|
| Target | ar7xxx/ar9xxx |
| Vendor | TP-Link |
| Bootloader | uboot |
| CPU Model | QCA9558 |
| CPU Speed | 720MHz |
| Flash chip | Winbond 25Q128FVSG (128 Mibit) |
| Flash size | 16 MiB |
| RAM chip | 2x Winbond W9751G6KB-25 (512 Mibit each) |
| RAM size | 128 MiB |
| WAN | In the original firmware LAN4 can act as WAN |
| Switch | AR8327N-BL1A |
| Ethernet | QCA8337 (4xGbe) |
| Wireless | QCA9558 (Integrated 2.4GHz) + QCA9880-BR4A (5GHz) |
| Serial | yes (see picture below) |
| Buttons | power switch, WPS button, Wifi on/off |
| Power | external 12V 2,5A |
To open the case you have to remove two screws underneath the information sticker and one screw below the silver front clip which should push forward, then you need to pry open the rest of the case which is clipped together (2×3 side clips; 2 front clips; 2 back clips).
J1
• VCC • GND • RX ▣ TX
Configure your favorite terminal with the following settings: 115200 baud, 8 bit, no parity, 1 stop bit, no flow control.
To enter into the bootloader, press “t” when it says: “Hit any key to stop autoboot”
Default user and password for console login inside the original OEM firmware is admin/1234
Since opening the case is relatively hard (because of the hard to remove silver clip and strong plastic clips), the easiest way to gain Serial access is by using some snips to cut out part of the case.
~ # cat /proc/mtd dev: size erasesize name mtd0: 00020000 00010000 "u-boot" mtd1: 00140000 00010000 "kernel" mtd2: 00e50000 00010000 "rootfs" mtd3: 00010000 00010000 "radioDECT" mtd4: 00010000 00010000 "config" mtd5: 00010000 00010000 "romfs" mtd6: 00010000 00010000 "rom" mtd7: 00010000 00010000 "radio"
| Architecture | MIPS32 (MIPS74Kc) |
|---|---|
| Target | bcm63xx |
| Bootloader | CFE |
| CPU Model | BCM6318 |
| CPU Speed | 333MHz |
| Flash chip | Winbond 25Q16DVSIG (16 Mibit) |
| Flash size | 2 MiB |
| RAM chip | ESMT M12L128168A (128 Mibit) |
| RAM size | 16 MiB |
| WAN | RJ-11 |
| Serial | yes (see picture below) |
J41
• VCC • GND • RX ▣ TX
Default user and password for console login inside the original OEM firmware is admin/admin
# cat /proc/mtd dev: size erasesize name mtd0: 0011d000 00000000 "BCM63XX RootFS"
cat /proc/mtd dev: size erasesize name mtd0: 00020000 00010000 "u-boot" mtd1: 00140000 00010000 "kernel" mtd2: 00e50000 00010000 "rootfs" mtd3: 00010000 00010000 "radioDECT" mtd4: 00010000 00010000 "config" mtd5: 00010000 00010000 "romfs" mtd6: 00010000 00010000 "rom" mtd7: 00010000 00010000 "radio"
dd if=openwrt.bin of=openwrt-mtd1.bin bs=1 count=1179648 dd if=openwrt.bin of=openwrt-mtd2.bin bs=1 skip=1179648
or
dd if=openwrt.bin of=openwrt-mtd1.bin bs=1 count=1310720 dd if=openwrt.bin of=openwrt-mtd2.bin bs=1 skip=1310720
cd /var/usbdisk/sda1/
cat /dev/mtdblock1 > ./mtd1 ls -l
> -rwxrwxrwx 1 5309227 openwrt-mtd2.bin -rwxrwxrwx 1 1310720 openwrt-mtd1.bin -rwxrwxrwx 1 94821 flash_erase -rwxrwxrwx 1 109558 nandwrite drwxrwxrwx 2 16384 System Volume Information -rwxrwxrwx 1 1310720 mtd1
./flash_erase /dev/mtd1 0x0 0 ./flash_erase /dev/mtd2 0x0 0 ./nandwrite /dev/mtd1 openwrt-mtd1.bin -p ./nandwrite /dev/mtd2 openwrt-mtd2.bin -p
This hack is the same used for the w8970/w9980 https://forum.kitz.co.uk/index.php?topic=17108.105.
You'll need python3 and pycrypto to run this script. You can install pycrypto by:
Download this python script: https://github.com/sta-c0000/tpconf_bin_xml/blob/master/tpconf_bin_xml.py
python3 tpconf_bin_xml.py -n conf.bin conf.xml
<Description val="Modem Router`telnetd -p 1023 -l login`" />
<?xml version="1.0"?>
<DslCpeConfig>
<InternetGatewayDevice>
<DeviceSummary val="InternetGatewayDevice:1.1[](Baseline:1, EthernetLAN:1)" />
<LANDeviceNumberOfEntries val=1 />
<DeviceInfo>
<ManufacturerOUI val=XXXXXX />
<SerialNumber val=XXXXXXXXXXXXX />
<HardwareVersion val="Archer D7 v1 00000002" />
<SoftwareVersion val="1.6.0 0.9.1 v002d.0 Build 160216 Rel.57110n" />
<UpTime val=4 />
<X_TP_IsFD val=3 />
</DeviceInfo>
...
<?xml version="1.0"?>
<DslCpeConfig>
<InternetGatewayDevice>
<DeviceSummary val="InternetGatewayDevice:1.1[](Baseline:1, EthernetLAN:1)" />
<LANDeviceNumberOfEntries val=1 />
<DeviceInfo>
<ManufacturerOUI val=XXXXXX />
<SerialNumber val=XXXXXXXXXXXXX />
<HardwareVersion val="Archer D7 v1 00000002" />
<SoftwareVersion val="1.6.0 0.9.1 v002d.0 Build 160216 Rel.57110n" />
<UpTime val=4 />
<X_TP_IsFD val=3 />
<Description val="Modem Router`telnetd -p 1023 -l login`" />
</DeviceInfo>
....
python3 tpconf_bin_xml.py conf.xml conf_new.bin
telnet 192.168.1.1 1023