ELECOM WRC-X1800GS

ELECOM is a popular local brand in Japan. WRC-X1800GS is a home router for small apartments and houses. It's a discontinued product but is widely available in numerous 2nd hand shops and marketplaces like Mercari for a very reasonable price.

Pros:

  • it is WiFi6 (11ax) capable
  • a good DRAM/flash configuration to run OpenWrt
  • easy to flash from stock

Cons:

  • only 3 eth ports
  • a bit outdated CPU platform

ELECOM WRC-X1800GS

WRC-X1800GS has 2x HW revisions. There are some small changes, but the same DeviceTree in stock firmware is used for both revisions.

Flash instruction using initramfs-factory image

(from openwrt/openwrt/commit/?id=50ae9337d62ce7991f80436eadf4415179c039d2):

1. Boot WRC-X1800GS normally with “Router” mode

2. Access to “http://192.168.2.1/” and open firmware update page (“ファームウェア更新”)

3. Select the OpenWrt initramfs-factory image and click apply (“適用”) button

4. After flashing initramfs-factory image and reboot, upload the sysupgrade image and perform sysupgrade with it

5. Wait ~120 seconds to complete flashing

Stock firmware uses dual-boot layout. There are two firmware slots, on upgrade stock firmware writes update to next inactive slot and switches to U-Boot boot flag to use updated slot on next boot. OpenWrt does not use dual-boot, so it is installed into slot1 and u-boot is configured to boot from it via update script.

MTD Partition Name Size (Hex) Size (MiB) Physical Flash Range (Hex)
mtd0 u-boot 0x00100000 1.0 MiB 0x00000000 - 0x00100000
mtd1 u-boot-env 0x00100000 1.0 MiB 0x00100000 - 0x00200000
mtd2 factory 0x001C0000 1.75 MiB 0x00200000 - 0x003C0000
mtd3 firmware 0x03240000 50.25 MiB 0x003C0000 - 0x03600000
mtd6 Config 0x00100000 1.0 MiB 0x03600000 - 0x03700000
mtd7 firmware2 0x03240000 50.25 MiB 0x03700000 - 0x06940000
mtd8 Config_2 0x00100000 1.0 MiB 0x06940000 - 0x06A40000
mtd9 persist 0x00100000 1.0 MiB 0x06A40000 - 0x06B40000
mtd10 mesh 0x00100000 1.0 MiB 0x06B40000 - 0x06C40000
mtd11 backup 0x01340000 19.25 MiB 0x06C40000 - 0x08000000
  • Browse to http://192.168.1.1/cgi-bin/luci/mini/system/upgrade/ LuCI Upgrade URL
  • Upload image file for sysupgrade to LuCI
  • Wait for reboot

If you don't have a GUI (LuCI) available, you can alternatively upgrade via the command line. There are two command line methods for upgrading:

  • sysupgrade
  • mtd

Note: It is important that you put the firmware image into the ramdisk (/tmp) before you start flashing.

sysupgrade

  • Login as root via SSH on 192.168.1.1, then enter the following commands:
cd /tmp
wget https://downloads.openwrt.org/releases/XX.XX.X/targets/ramips/mt7621/elecom_wrc-x1800gs-squashfs-sysupgrade.bin
sysupgrade /tmp/elecom_wrc-x1800gs-squashfs-sysupgrade.bin
  • download vendor fw image
  • unzip && upload fw image to /tmp
  • Flash vendor image via mtd write wrc-x1800gs_v1.21.bin firmware2
  • switch u-boot to boot from `image2`
  . /lib/upgrade/iodata.sh
  iodata_mstc_set_flag "bootnum" "persist" "0x4" "1,2" "2"

Then reboot your router, waiting it finished rollback in minutes.

The default network configuration is:

Interface Name Description Default configuration
br-lan LAN & WiFi 192.168.1.1/24
lanX (eth0) LAN ports (1-2) None
wan (eth0) WAN port DHCP
phy0-ap0 WiFi 2.4G Disabled
phy1-ap0 WiFi 5G Disabled

→ hardware.button on howto use and configure the hardware button(s). Here, we merely name the buttons, so we can use them in the above Howto.

The ELECOM WRC-X1800GS has the following buttons:

BUTTON Event
Reset reset
WPS WiFi WPS
AP Switch Switch route/AP mode

Router has two internal antennas, combined 2.4/5 GHz. The main PCB has two standard IPEX1 (U.FL) terminals where PCB-shaped antennas are attached with pig-tails.

Front:
wrc-x1800gs front

Back:
wrc-x1800gs back

Backside label:
wrc-x1800gs side

→ Warranty

* To remove the cover and open the device, unscrew two screws on the bottom side and carefully unlock plastic clips with something like a plastic card or screwdriver. There are 3 clip at front side (where LEDs are located) and one clip at the back side (below mode switch).

Main PCB:

→ port.serial general information about the serial port, serial port cable, etc.

Serial pins are presoldered on a board, just connect to it with jump-wires. Pins order is: Vcc, Tx, Rx, Gnd - if counted from heat-sink downward to the PCB edge.

Serial port setup
115200, 8N1, 3.3V

\Stock U-Boot has bootmenu_delay param set to “0”, so you won't be able to enter boot menu on stock FW. But after flashing OpenWrt it will be set to 3 sec and boot menu would become available.

None so far.

=================================================================== MT7621 stage1 code Dec 16 2019 17:45:55 (ASIC) CPU=500000000 HZ BUS=166666666 HZ ================================================================== Change MPLL source from XTAL to CR... do MEMPLL setting.. MEMPLL Config : 0x11000000 3PLL mode + External loopback === XTAL-40Mhz === DDR-1200Mhz === PLL3 FB_DL: 0xc, 1/0 = 580/444 31000000 PLL2 FB_DL: 0x12, 1/0 = 567/457 49000000 PLL4 FB_DL: 0x14, 1/0 = 530/494 51000000 DDR patch working do DDR setting..[01F40000] Apply DDR3 Setting...(use default AC) 0 8 16 24 32 40 48 56 64 72 80 88 96 104 112 120 -------------------------------------------------------------------------------- 0000:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0001:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0002:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0003:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0004:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0005:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0006:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0007:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0008:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0009:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 000A:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 000B:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 000C:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 000D:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 000E:| 0 0 0 0 0 0 0 0 0 0 1 1 1 1 1 1 000F:| 0 0 0 0 0 1 1 1 1 1 1 1 1 1 1 1 0010:| 1 1 1 1 1 1 1 1 1 1 1 0 0 0 0 0 0011:| 1 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0012:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0013:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0014:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0015:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0016:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0017:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0018:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0019:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 001A:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 001B:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 001C:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 001D:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 001E:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 001F:| 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 DRAMC_DQSCTL1[0e0]=14000000 DRAMC_DQSGCTL[124]=80000000 rank 0 coarse = 16 rank 0 fine = 40 B:| 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 opt_dle value:9 DRAMC_DDR2CTL[07c]=C287221D DRAMC_PADCTL4[0e4]=000022B3 DRAMC_DQIDLY1[210]=0C0B0A0C DRAMC_DQIDLY2[214]=090C090B DRAMC_DQIDLY3[218]=0A080707 DRAMC_DQIDLY4[21c]=09060A08 DRAMC_R0DELDLY[018]=00002022 ================================================================== RX DQS perbit delay software calibration ================================================================== 1.0-15 bit dq delay value ================================================================== bit| 0 1 2 3 4 5 6 7 8 9 -------------------------------------- 0 | 9 9 10 11 9 9 9 8 6 6 10 | 8 8 8 9 6 9 -------------------------------------- ================================================================== 2.dqs window x=pass dqs delay value (min~max)center y=0-7bit DQ of every group input delay:DQS0 =34 DQS1 = 32 ================================================================== bit DQS0 bit DQS1 0 (1~61)31 8 (1~62)31 1 (1~66)33 9 (0~62)31 2 (2~65)33 10 (0~64)32 3 (1~65)33 11 (1~60)30 4 (1~64)32 12 (1~64)32 5 (2~66)34 13 (1~62)31 6 (1~61)31 14 (1~63)32 7 (1~66)33 15 (1~63)32 ================================================================== 3.dq delay value last ================================================================== bit| 0 1 2 3 4 5 6 7 8 9 -------------------------------------- 0 | 12 10 11 12 11 9 12 9 7 7 10 | 8 10 8 10 6 9 ================================================================== ================================================================== TX perbyte calibration ================================================================== DQS loop = 15, cmp_err_1 = ffff0000 dqs_perbyte_dly.last_dqsdly_pass[0]=15, finish count=1 dqs_perbyte_dly.last_dqsdly_pass[1]=15, finish count=2 DQ loop=15, cmp_err_1 = ffff0000 dqs_perbyte_dly.last_dqdly_pass[0]=15, finish count=1 dqs_perbyte_dly.last_dqdly_pass[1]=15, finish count=2 byte:0, (DQS,DQ)=(8,8) byte:1, (DQS,DQ)=(8,8) DRAMC_DQODLY1[200]=88888888 DRAMC_DQODLY2[204]=88888888 20,data:88 [EMI] DRAMC calibration passed =================================================================== MT7621 stage1 code done CPU=500000000 HZ BUS=166666666 HZ =================================================================== U-Boot 1.41.05 (Feb 24 2021 - 15:08:53) Trying to boot from NAND U-Boot 1.41.05 (Feb 24 2021 - 15:08:53) CPU: MediaTek MT7621AT ver 1, eco 3 Clocks: CPU: 880MHz, DDR: 1200MHz, Bus: 220MHz, XTAL: 40MHz Model: MediaTek MT7621 reference board (NAND) DRAM: 256 MiB NAND: 128 MiB Loading Environment from NAND... OK In: uartlite0@1e000c00 Out: uartlite0@1e000c00 Err: uartlite0@1e000c00 Net: eth0: eth@1e100000 gpio: pin 4 (gpio 4) value is 1 *** U-Boot Boot Menu *** 1. Startup system (Default) 2. Upgrade firmware 3. Upgrade bootloader 4. Upgrade bootloader (advanced mode) 5. Load image 6. Upgrade mtkfirmware 0. U-Boot console <nowiki> ==== OEM bootlog ==== <WRAP bootlog> <nowiki>bootnum =2 Checking FW2 combo magic and checksum ... OK. Loading from nand0, offset 0x3740000 Fit image detected... FIT description: MIPS OpenWrt FIT (Flattened Image Tree) Image 0 (kernel@1) Description: MIPS OpenWrt Linux-4.4.198 Type: Kernel Image Compression: lzma compressed Data Start: 0x820000e4 Data Size: 3566463 Bytes = 3.4 MiB Architecture: MIPS OS: Linux Load Address: 0x81001000 Entry Point: 0x81001000 Hash algo: crc32 Hash value: 5726d942 Hash algo: sha1 Hash value: df3c45e73b2f8132fb62eacc9fd106368c140eb2 Image 1 (fdt@1) Description: MIPS OpenWrt mt7621-rfb-ax-nand device tree blob Type: Flat Device Tree Compression: uncompressed Data Start: 0x82366da8 Data Size: 11318 Bytes = 11.1 KiB Architecture: MIPS Hash algo: crc32 Hash value: a5c0dc38 Hash algo: sha1 Hash value: 965c4c04eb2ba5655345f61aa88a3771329ade55 Default Configuration: 'config@1' Configuration 0 (config@1) Description: OpenWrt Kernel: kernel@1 FDT: fdt@1 Automatic boot of image at addr 0x82000000 ... ## Loading kernel from FIT Image at 82000000 ... Using 'config@1' configuration Trying 'kernel@1' kernel subimage Description: MIPS OpenWrt Linux-4.4.198 Type: Kernel Image Compression: lzma compressed Data Start: 0x820000e4 Data Size: 3566463 Bytes = 3.4 MiB Architecture: MIPS OS: Linux Load Address: 0x81001000 Entry Point: 0x81001000 Hash algo: crc32 Hash value: 5726d942 Hash algo: sha1 Hash value: df3c45e73b2f8132fb62eacc9fd106368c140eb2 Verifying Hash Integrity ... crc32+ sha1+ OK ## Loading fdt from FIT Image at 82000000 ... Using 'config@1' configuration Trying 'fdt@1' fdt subimage Description: MIPS OpenWrt mt7621-rfb-ax-nand device tree blob Type: Flat Device Tree Compression: uncompressed Data Start: 0x82366da8 Data Size: 11318 Bytes = 11.1 KiB Architecture: MIPS Hash algo: crc32 Hash value: a5c0dc38 Hash algo: sha1 Hash value: 965c4c04eb2ba5655345f61aa88a3771329ade55 Verifying Hash Integrity ... crc32+ sha1+ OK Booting using the fdt blob at 0x82366da8 Uncompressing Kernel Image ... OK Loading Device Tree to 8fe77000, end 8fe7cc35 ... OK [ 0.000000] Linux version 4.4.198 (cmtien@idbgitlab) (gcc version 5.4.0 (OpenWrt GCC 5.4.0 709e1fb7) ) #1 SMP Tue Mar 10 12:48:59 CST 2026


bootnum =2 Checking FW2 combo magic and checksum ... OK. Loading from nand0, offset 0x3740000 Fit image detected... FIT description: MIPS OpenWrt FIT (Flattened Image Tree) Image 0 (kernel@1) Description: MIPS OpenWrt Linux-4.4.198 Type: Kernel Image Compression: lzma compressed Data Start: 0x820000e4 Data Size: 3566463 Bytes = 3.4 MiB Architecture: MIPS OS: Linux Load Address: 0x81001000 Entry Point: 0x81001000 Hash algo: crc32 Hash value: 5726d942 Hash algo: sha1 Hash value: df3c45e73b2f8132fb62eacc9fd106368c140eb2 Image 1 (fdt@1) Description: MIPS OpenWrt mt7621-rfb-ax-nand device tree blob Type: Flat Device Tree Compression: uncompressed Data Start: 0x82366da8 Data Size: 11318 Bytes = 11.1 KiB Architecture: MIPS Hash algo: crc32 Hash value: a5c0dc38 Hash algo: sha1 Hash value: 965c4c04eb2ba5655345f61aa88a3771329ade55 Default Configuration: 'config@1' Configuration 0 (config@1) Description: OpenWrt Kernel: kernel@1 FDT: fdt@1 Automatic boot of image at addr 0x82000000 ... ## Loading kernel from FIT Image at 82000000 ... Using 'config@1' configuration Trying 'kernel@1' kernel subimage Description: MIPS OpenWrt Linux-4.4.198 Type: Kernel Image Compression: lzma compressed Data Start: 0x820000e4 Data Size: 3566463 Bytes = 3.4 MiB Architecture: MIPS OS: Linux Load Address: 0x81001000 Entry Point: 0x81001000 Hash algo: crc32 Hash value: 5726d942 Hash algo: sha1 Hash value: df3c45e73b2f8132fb62eacc9fd106368c140eb2 Verifying Hash Integrity ... crc32+ sha1+ OK ## Loading fdt from FIT Image at 82000000 ... Using 'config@1' configuration Trying 'fdt@1' fdt subimage Description: MIPS OpenWrt mt7621-rfb-ax-nand device tree blob Type: Flat Device Tree Compression: uncompressed Data Start: 0x82366da8 Data Size: 11318 Bytes = 11.1 KiB Architecture: MIPS Hash algo: crc32 Hash value: a5c0dc38 Hash algo: sha1 Hash value: 965c4c04eb2ba5655345f61aa88a3771329ade55 Verifying Hash Integrity ... crc32+ sha1+ OK Booting using the fdt blob at 0x82366da8 Uncompressing Kernel Image ... OK Loading Device Tree to 8fe77000, end 8fe7cc35 ... OK [ 0.000000] Linux version 4.4.198 (cmtien@idbgitlab) (gcc version 5.4.0 (OpenWrt GCC 5.4.0 709e1fb7) ) #1 SMP Tue Mar 10 12:48:59 CST 2026


Checking FW1 combo magic and checksum ... OK. Loading from nand0, offset 0x400000 Fit image detected... FIT description: MIPS OpenWrt FIT (Flattened Image Tree) Image 0 (kernel-1) Description: MIPS OpenWrt Linux-6.12.94 Type: Kernel Image Compression: lzma compressed Data Start: 0x820000e4 Data Size: 3313090 Bytes = 3.2 MiB Architecture: MIPS OS: Linux Load Address: 0x88000000 Entry Point: 0x88000000 Hash algo: crc32 Hash value: c2099230 Hash algo: sha1 Hash value: ccdd8dca5b259f789c66c4226689f5145af95594 Image 1 (fdt-1) Description: MIPS OpenWrt elecom_wrc-x1800gs device tree blob Type: Flat Device Tree Compression: uncompressed Data Start: 0x82328fec Data Size: 14040 Bytes = 13.7 KiB Architecture: MIPS Hash algo: crc32 Hash value: 89284528 Hash algo: sha1 Hash value: 180e57d8939000b03091dd57df35d16691601bc4 Default Configuration: 'config-1' Configuration 0 (config-1) Description: OpenWrt elecom_wrc-x1800gs Kernel: kernel-1 FDT: fdt-1 Automatic boot of image at addr 0x82000000 ... ## Loading kernel from FIT Image at 82000000 ... Using 'config-1' configuration Trying 'kernel-1' kernel subimage Description: MIPS OpenWrt Linux-6.12.94 Type: Kernel Image Compression: lzma compressed Data Start: 0x820000e4 Data Size: 3313090 Bytes = 3.2 MiB Architecture: MIPS OS: Linux Load Address: 0x88000000 Entry Point: 0x88000000 Hash algo: crc32 Hash value: c2099230 Hash algo: sha1 Hash value: ccdd8dca5b259f789c66c4226689f5145af95594 Verifying Hash Integrity ... crc32+ sha1+ OK ## Loading fdt from FIT Image at 82000000 ... Using 'config-1' configuration Trying 'fdt-1' fdt subimage Description: MIPS OpenWrt elecom_wrc-x1800gs device tree blob Type: Flat Device Tree Compression: uncompressed Data Start: 0x82328fec Data Size: 14040 Bytes = 13.7 KiB Architecture: MIPS Hash algo: crc32 Hash value: 89284528 Hash algo: sha1 Hash value: 180e57d8939000b03091dd57df35d16691601bc4 Verifying Hash Integrity ... crc32+ sha1+ OK Booting using the fdt blob at 0x82328fec Uncompressing Kernel Image ... OK Loading Device Tree to 8fe76000, end 8fe7c6d7 ... OK


Space for additional notes, links to forum threads or other resources.

  • ...

FIXME Add tags below, then remove this fixme.

How to add tags

  • Last modified: 2026/10/01 09:17
  • by vortigont