Keenetic Buddy 6 (KN-3411) and Buddy 6 SE (KN-4410)

The Keenetic Buddy 6 (KN-3411) is a dual-band Wi-Fi 6 mesh extender on MediaTek MT7981B with 256 MiB RAM, 128 MiB SPI-NAND and a single gigabit Ethernet port. The Buddy 6 SE (KN-4410) and the Netcraze Buddy 6 (NC-3411) and Buddy 6 SE (NC-4410) are the same board and firmware; the SE comes in a different case with internal antennas instead of two external ones. Everything on this page applies to all four, with the model name in the image and recovery file names.

Generic Router

→ generic.flashing.tftp

The stock bootloader has a TFTP recovery mode. It takes 192.168.1.1 itself and asks 192.168.1.2 for the image.

  1. Connect the TFTP host to the Ethernet port and give it the address 192.168.1.2. The host must not own 192.168.1.1: the bootloader uses that address as its own, and a host that has it drops the bootloader's ARP requests as a conflict.
  2. Take the squashfs-factory.bin image for your brand and rename it to <model>_recovery.bin, for example KN-3411_recovery.bin or NC-4410_recovery.bin. Put it in the TFTP directory.
  3. Power off the device, hold the Reset button, power it on and keep the button held for about 10 seconds.
  4. Wait for the reboot. OpenWrt comes up on 192.168.1.1.

The stock recovery accepts only images signed for its own brand and model, so each of the four needs its own image.

Specific values needed for tftp

Bootloader tftp server IPv4 address 192.168.1.2 (the TFTP host)
Bootloader own IPv4 address 192.168.1.1
Firmware tftp image <model>_recovery.bin (KN-3411, NC-3411, KN-4410 or NC-4410)

Download the official recovery package for your model, KN-3411, KN-4410, NC-3411 or NC-4410, take the .bin out of it and repeat the TFTP steps above with that file in place of the OpenWrt image.

As on the other Keenetic MT7981 devices, both vendor firmware slots are joined into one UBI volume. After installing OpenWrt there is no second vendor slot to fall back to; the TFTP recovery above is the way back.

→ generic.sysupgrade

Use the squashfs-sysupgrade.bin image, from LuCI or with sysupgrade on the command line.

→ generic.debrick

The vendor TFTP recovery described above works as long as the stock bootloader is intact, which OpenWrt does not overwrite.

→ Basic configuration After flashing, proceed with this.

Interface Name Description Default configuration
br-lan Ethernet port eth0 192.168.1.1/24

There is no WAN interface: the single port is LAN.

→ hardware.button on howto use and configure the hardware button(s).

BUTTON Event
Reset reset
LED Colour
Status green
WLAN 2.4 GHz red
WLAN 5 GHz blue

The LED and button GPIO map is not published by the vendor and is compiled into a stock kernel module, so these values were confirmed on hardware.

Interface Source
eth0 rf-eeprom 0x4

  • SoC: MediaTek MT7981B
  • RAM: 256 MiB
  • Flash: 128 MiB SPI-NAND. Any of the four models can ship with either Winbond W25N01GV or HeYangTek HYF1GQ4UDACAE, with no PCB revision marker to tell them apart. Both chips are supported.
  • Ethernet: 1x 1GbE, MT7981 internal PHY
  • Wi-Fi: MT7981 2×2, 2.4 GHz and 5 GHz

→ port.serial

Serial connection parameters 115200, 8N1
  • Support was added in PR #23727, based on the reverse engineering by Maxim Anisimov in PR #15551.
  • Last modified: 2026/09/28 00:22
  • by lexfrei