Keenetic KN-1012 (Hero/Giga)

The Keenetic KN-1012 is a dual-band Wi-Fi 6 router on MediaTek MT7981B with 512 MiB RAM and 256 MiB SPI-NAND. Besides four gigabit ports it has a combo port: an RJ45 through an Airoha EN8811H 2.5G PHY and an SFP cage, used one at a time. The same hardware is sold as the Netcraze NC-1012; everything on this page applies to it, with NC-1012 in the image and recovery file names.

Generic Router

Snapshot

→ Install OpenWrt (generic explanation)

The vendor bootloader stays in place, so its TFTP recovery keeps working as the way back. OpenWrt boots a second U-Boot from it, which picks the device tree for the medium in the combo port and then starts the kernel.

→ generic.flashing.tftp

  1. Connect the TFTP host to one of the LAN ports and give it the address 192.168.1.2.
  2. Take the squashfs-factory.bin image for your brand and rename it to KN-1012_recovery.bin (Keenetic) or NC-1012_recovery.bin (Netcraze). Put it in the TFTP directory.
  3. Power off the router, hold the Reset button, power it on and keep the button held for about 10 seconds.
  4. The bootloader downloads the image and writes it to flash.
  5. Wait for the reboot. OpenWrt comes up on 192.168.1.1.

The stock recovery accepts only images signed for its own brand, so a Keenetic image does not install on an NC-1012 and the other way round.

Specific values needed for tftp

Bootloader tftp server IPv4 address 192.168.1.2 (the TFTP host)
Firmware tftp image KN-1012_recovery.bin or NC-1012_recovery.bin

Download the official recovery package, KN-1012 or NC-1012, take the .bin out of it and repeat the TFTP steps above with that file in place of the OpenWrt image.

The two vendor firmware slots (firmware_1, storage_a, firmware_2, storage_b) are joined into one virtual flash device. Its first 8 MiB are the kernel partition and the rest is ubi. After installing OpenWrt the second slot no longer holds a vendor-bootable image. u-state stays read-only.

Name Offset Size
preloader 0x00000000 0x00080000
u-boot 0x00080000 0x00200000
u-config 0x00280000 0x00080000
rf-eeprom 0x00300000 0x00200000
firmware_1 0x00500000 0x03a00000
config_1 0x03f00000 0x00080000
dump 0x03f80000 0x00080000
storage_a 0x04000000 0x03800000
u-state 0x07800000 0x00020000
oopslog 0x07820000 0x00260000
u-config_res 0x07a80000 0x00080000
rf-eeprom_res 0x07b00000 0x00200000
firmware_2 0x07d00000 0x03a00000
config_2 0x0b700000 0x00080000
storage_b 0x0b780000 0x03880000
kernel (virtual) - 0x00800000
ubi (virtual) - 0x0dc80000

→ generic.sysupgrade

Use the squashfs-sysupgrade.bin image, from LuCI or with sysupgrade on the command line.

→ generic.debrick

The vendor TFTP recovery described above works as long as the stock bootloader is intact, which OpenWrt never overwrites.

→ Basic configuration After flashing, proceed with this.
Set up your Internet connection, configure wireless, configure USB port, etc.

The default network configuration is:

Interface Name Description Default configuration
br-lan LAN ports lan1 to lan4 192.168.1.1/24
wan WAN port DHCP
wan6 WAN port DHCPv6

The combo port is either copper or SFP, never both. The second U-Boot checks at every boot whether an SFP module is present and loads the matching device tree, so to change the medium, plug or unplug the module and reboot. With a module in the cage and a cable in the RJ45 at the same time, SFP wins.

  • SFP: works. The port advertises 2500BASE-X, its native mode. A 10G DAC against a partner that does only 1G or 10G gets no link until ethtool -s lan4 advertise 0x20000000000 drops it to 1000BASE-X. A plain 1G module should be picked up on its own.
  • Copper: does not come up yet on snapshot builds. The EN8811H driver loads its firmware from the root filesystem, after the switch has already attached the PHY. The kernel fix is on the netdev list and its OpenWrt backport is PR #24819. Once that is merged, copper works with no change to the image.

→ hardware.button on howto use and configure the hardware button(s).

BUTTON Event
Reset reset
WPS wps
FN1 BTN_0
FN2 BTN_1
Interface Source
LAN rf-eeprom 0x4
WAN rf-eeprom 0xa, also the address on the label
2.4 GHz rf-eeprom 0x4
5 GHz rf-eeprom 0x4 with the locally administered bit set and bit 7 flipped

  • SoC: MediaTek MT7981B
  • Switch: MediaTek MT7531
  • Combo port: SFP cage and Airoha EN8811H 2.5G copper PHY on one SerDes, selected by a GPIO mux
  • Flash: 256 MiB SPI-NAND, the chip varies by production run (Fudan Micro FM25G02B seen)
  • USB: one USB 3.0 and one USB 2.0 port; USB 2.0 goes through a GL850G hub, each port has a switchable power rail. SuperSpeed under OpenWrt is not tested yet
  • Power: 12 VDC, 2.5 A, center positive

→ port.serial general information about the serial port, serial port cable, etc.

There is a through-hole header J500 on the PCB. Its assignment is unconfirmed: 5V, TX, RX, NC, GND.

Serial connection parameters
for Keenetic KN-1012
115200, 8N1
  • Support was added in PR #24820, based on the out-of-tree port by Maxim Anisimov.
  • The second U-Boot and the combo port handling are OpenWrt-specific. Mainline has no way yet to describe a port that switches between an SFP cage and a copper PHY at runtime, so the medium is chosen once per boot.
  • Last modified: 2026/09/28 00:15
  • by lexfrei