Photograph of BT voyager 205 router

The "Other Voyager Router" page.


The main page started getting a lot of non-205 action, particularly folk looking for ways to unlock the BT Voyager 2091 router to use with another ISP. Then it turns out that BT are adding this "capability" to other routers in their range. We know the 220, 210, and 2500 have been similarly nobbled, and perhaps others.

Here is a place, then, to share what we know so far. As we learn things, I will endeavour to put the information up here where you can easily get at it. Please note, I do not personally offer support or advice for these routers, simply provide a space where efforts to understand and hack these beasts can be coordinated. And a place to grab the hacked firmwares, of course.

What we know so far..

BT has started putting ISP-Locks on their routers. For a company that claims to be evironmentally friendly, this surely-criminal practice aims to create a mountain hardware that's soul function will be to pollute the environment. Our grandchildren will not thanks us.

While these devices are highly capable, they will be superceded, and unless we can bypass this insane "feature", discarding these perfectly functional units wil be the only option.

The BT Voyager 205 is not locked to any particular ISP, and when I eventually upgrade it, I will either pass it on to someone who needs it, or perhaps investigate turning the thing into an effects pedal. Hmm. What about the others..

210V ISP Unlocked!

The BT Voyager 210 has been cracked!
An unlocked firmware is available..

Check out the archive for an unlocked firmware.

The original email..
I added "_BB" to a file cfe-voyager210_roi-v301z_a2pb018c1
I downloaded from

https://www.voyager.bt.com/firmware_upgrades/btvoyager-one-click-fw-update

I calculated CRC32 on bytes 0-235 and put it in 4 bytes 236-239
I am using voyager 210 with non BT ISP !!!!!!!!!!
it is also uploaded to your blog ftp !!!!!!!

host it and let's see feedback from ppl with 210 !!!!!!!!!
please keep my name private !!!!!!!
And there you have it. If it works, or doesn't, leave feedback, below.

220V ISP Unlocked!

The BT Voyager 220 has been cracked!
An unlocked firmware is available..

An unlocked firmware is available in the archive. There's also a copy of the original Pre-Lock v1.6 firmware, courtesy of Mark Eldon, which should take your 220V back to a time when BT had a clue. As well as firmwares for the 220, there's also this cute JavaScript hack..

Big thanks and full credits go to C1 (lost1e (at) hotmail (dot) com) for the following, extremely cute hack. In his own words, roughly..

I just bypassed the domainLock on a new BT voyager [220V] that I was trying to get working on Eclipse for a friend.

No need to mess about with firmware or process lists, the solution really is incredibly simple thanks to a little JavaScript magic :)

1. Navigate (using Internet Explorer, FireFox is untested) to this URL:
http://192.168.1.1/connect.html (replace IP with whatever your voyager is)
The purpose of this is to make the connect page the only frame - other frames screw up the JavaScript below.

2. Open Notepad, and type in the following text exactly as it appears:
javascript:function C1() { if (domainLock == 1) { domainLock = 0; } } C1();
(the above must be all on 1 line).

3. You will notice that the connect page in your router refreshes every 10-20 seconds or so. After the next refresh, immediately copy and paste the text in step 2 into the URL bar of Internet Explorer and hit ENTER.

4. It will seem to you like nothing has happened - but now just enter (or preferably paste) your new ISP details in and hit connect - no more annoying "unsupported broadband service" message smilie for :D You must do all of this before the next refresh happens - so have everything ready in notepad for quick pasting.

IMPORTANT NOTE: This worked for me *AFTER* I had actually set up my new ISP (Eclipse) in the router's Telnet CLI - you will have to do this first. WAN settings are always VPI:0 VCI:38 PPPoATM, VCMUX encapsulation, and most other stuff can be left as default except your new ISP details. The above 4 steps simply allow you to CONNECT with your new ISP details AFTER the details are saved in the router.

This new hack has been confirmed to work with the Voyager 220V. But not other ISP-locked BT Voyager routers like the Voyager 210. If you have such a device, feel free to give it a try and leave feedback below!

Note: even the older Voyager 220 is still locked into BT's VOIP service, and at the time of writing, no way to unlock this aspect of its functionality is known. If you know better, please get down to the commment form!

BT Voyager 2091 UNLOCKED!

The BT Voyager 2091 has been cracked!
An unlocked firmware is available..

Apart from a rare and early release, all versions of the BT Voyager 2091 are "ISP-Locked", that is, BT has locked it so you can't use them with another ISP. More recently, 2091 users have unlocked it..

Extra big packet of Jube Jubes to Alessio for figuring out how to turn a Dynalink 1050W firmware into a working BT Voyager 2091 firmware (with a little help from SkayaWiki ), in his own words..

Hi,
I tried to put the Dynalink 1050W <https://www.dynalink.com.au/firmware.htm?prod=RTA1025W> firmware in my BT voyager 2091 Wireless router - they both use the BCM6348 Chipset (check the brochure https://www.dynalink.com.au/modemsadsl_cur.htm?prod=RTA1025W).

I did this pretty much what I found on https://skaya.enix.org/wiki/FirmwareFormat:

From the Voyager2091 - cfe-voyager2091_btr-v301m-a2pb018c1 I took from the very beginning of the file

36 00 00 00 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 56 32 30 39 31 5F 42 42 00 00 00 00 00 00 00 00 31 00

and copied into cfe-rta1025wnz-v328q_a2pb01. The first section of the firmware contains data about the vendor: now the Dynalink 1050w "sounds" like a Voyager 2091.

In the modified Dynalink 1050W firmware, I was not keen on touching the following section which contains size/address of loader/rootfs (this could make your router unusable!)
I calculated the checksum with flipped bits:

bytes 236-239: contains the checksum from byte 0 to byte 255 - the checksum is 43 6C F1 22

byte 216-219: contains the checksum from byte 256 to the end of file - the checksum is 82 12 7F 96

Then I saved the firmware and uploaded to the Voyager via web interface, the upload went fine and the Voyager rebooted, it went up without any problem.

Alessio is on BT himself, so Paulo whipped out his copy of XVI32, did the dirty with the two firmwares files, and successfully connected his 2091 to AOL. The rest, as they say, is history. *g*

Check out the Useful links section below for the file you need. Then follow this simple procedure (adapted from Dan's comment)..



2500V ISP Unlocked!

The BT Voyager 2500 has been cracked!
An unlocked firmware is available..

A firmware in the archive (untested). I have a few of these kicking around. If anyone has problems with any of the firmwares, leave a comment below, and I'll track down one of the others.

Voyager GPL Firmware..

Part of that many Voyager firmwares is GPL, and publicly available; we have recently aquired this. At this early stage, not much hacking as been done. If you want to download the firmware and have a crack at it yourself, the releases (as shipped for free on CD from BT) are available here..

Before you ask a question..

If you have a BT Voyager 205 router, try the main page . This is for the other routers. Feel free to ask questions, give advice, drop information, etc..


previous comments (fourty pages)   show all comments

xenaxel - 07.06.06 5:33 pm

does anyone know how to unlock the bt hub (inventel DV4212)


Wonko - 09.06.06 11:46 am

You can telnet the 210 and you get a menu. However, you are not restricted to using that menu. Its a bit like the old menus we used in DOS. IE you get a cursor and you are prompted to type 1 - 5, but you can actually type whatever you want.



jukeboxwizard - 12.06.06 6:43 pm

Ok folks...here's the lowwww down so far on the Voyager 2500V...but first...welcome back Corz.org...I thought BT had smothered ya in legal claims for a moment there smiley for ;)

Ok folks...the BT Voyager 2500V is in fact as I suspected...see earlier post up there ^ somewhere...
It is in fact the spanking new Dynalink RTA1046VW Mark II
complete with all the trinkets and goodies ya can expect from such a combination device like this...
After I have a few cups of coffee and get to wiring in my extension etc...I'll settle down and have a play with it....in the meantime...anyone with the new Dynalink firmware for this router shouldn't have any more lock problems I hope...

rgds


jukeboxwizard - 12.06.06 6:57 pm

actually...on a side note...it makes me wonder if the BT 2091 is in fact the RTA770W...anyone care to comment ?

rgds

p.s. ignore that brain fart...it's more likely the RTA1025W...


DIGITALDAZZ - 12.06.06 10:46 pm

hi all,

just a quick question, as I now have the modded firmware on my 2091 can i update to the original firmware or any updates that come from dynalink?


cheers


Giles - 13.06.06 12:18 am

Surely we don't need to export the old firmware - just need to edit the new one from BT to disable all these stupid lock downs. A link to the new one is posted somewhere in the above thread. Anyone familiar with editing a firmware?

If this is the new Dynalink RTA1046VW Mark II then a link to this firmware will mean that my search (and time) has not been in vain!


Giles - 13.06.06 12:22 am

Anyone that hadn't guessed (and I hadn't mentioned it) this is the new 2500V that I'm talking about.

Welcome back online corz.org!


jukeboxwizard - 13.06.06 7:11 am

Ok folks...I had a quicksie look under the bonnet so to speak and here is what I know so far about the 2500V...it is for sure and certain the new Askey/Dynalink RTA1046VW. Though I'm buggered if I can find out anything much about it from the manufacturers, let alone any support for it.
Major chipset and associated passives in no particular order are as follows:-

BCM6348KPBG - Single chip Adsl2+ controller.
BCM5325EK - Single chip 5 Port ethernet switch using LANKom's SQ-H48W 100baseT magnetics package.

BCM6341KPBG - I assume single chip router solution.
BCM4318 - Single chip Wireless Lan controller.
M12L64164A * 2 - 4mb by 16 3.3v asyncronous sdram - I assume configured as 8mb * 16.
IS61LV6416-10T - 64K * 16 asyncronous sram.
LE9502BTC - Legerity Voslic (Voice Over Subscriber Line Interface)
BCM6301 - 5V adsl2+ line driver chip and associated Linkcom LaL0683 Annex-A adsl2+ transformer.
CP152's * 2 - Tansient voltage protection for slic.
MP1410ES - 2amp DC-DC converter ic, awfully similar to ACT4060 in fact, in any case this one is made by Monolithic Power Semiconductors, but obviously they deny it's existance.
S29GL064M90TFIR4 - Spansion 64K * 16 Flash memory chip, I'm guessing this is where BT hid their dirty linen.

I haven't played with the firmware as yet, not even been in the settings beyond the status, so I have no real comments as yet, save this, I did try testing out the upgrade mechanism and found out that there is indeed a valid firmware upgrade to version 3.01N from BT,
the firmware as it was shipped is version 2.21.05.11G
For those of you mad enough or remotely interested in seeing what this animal actually looks like, I took a few pics for ya, and I will upload them to the public archive. The filename is "Inside the 2500V.rar" and is just shy of 7mb.

I have sent Askey an email asking them for a copy of the firmware, I await their reply, as they obviously don't manufacture this router for Dynalink, or you would think so with the lack of support, it will be interesting to see how they deal with my request. I will also email BT when I get a chance and ask them for a copy of the non-locked version too - we shall see...

I have the equipment and the expertise to remove the flash chip, read/program it and replace it back on board etc, but I see this as pointless due to my firmware being of the locked variety, so if anyone has a knackered one of these 2500V's with the unlocked firmware, contact me and I'll arrange something.

In the meantime I will look into some other ways to pull out the firmware without resorting to a board rework.
Of course, I expect a little help from you guys too smiley for :)


rgds


jukeboxwizard - 13.06.06 7:31 am

Which brings me to another point Cor!!!

can you move that file into the public archive somewhere smiley for :lol:

rgds


cor - 13.06.06 5:06 pm

jukeboxwizard said..
I thought BT had smothered ya in legal claims for a moment there

That was the first thing that crossed my mind, too, jukeboxwizard! smiley for :lol:

So, the 2500 is a re-branded Dynalink RTA1046VW Mark II, excellent news! Hopefully it should only be a matter of time before its firmware can be adapted. (Giles, go for it!)

Hey! I found the file! (I forget about the uploads folder until someone reminds me!) and I've upped the images I got to the "circuit board" folder in the archives. The archive was truncated, strangely, so there's a couple missing (feel free to mail me the others). Also note, I reduced the pics to half size.

Thanks for all the info and images, jukeboxwizard, always appreciated. By the way, I can accept a gigabyte in my email, too, give or take.

DIGITALDAZZ, No, you can't upgrade the 2091 with future Dynalink firmwares, UNLESS you apply a hack similar to the one above. If they release a new firmware, I do hope someone does exactly that!

l*rz..

;o)


patrick - 13.06.06 9:19 pm

Hello Folks -
thank you for the hack unlocking the 2091...
i have been following this site for a long while and sooo pleased there are excellent tech-minded people out there
just one question: i have managed to unlock the 2091, but it seems to refuse to run on wireless...

Any suggestions would be hugely welcome!

thanks
P


next comments (8 pages)

Posting here is disabled at this time.

Welcome to corz.org!

I'm always messing around with the back-end.. See a bug? Wait a minute and try again. Still see a bug? Mail Me!