Hacking QNAP QSW-m2116p-2t2s

Notice: Page may contain affiliate links for which we may earn a small commission through services like Amazon Affiliates or Skimlinks.

michaels2408

New Member
Jun 10, 2021
2
1
3
Good evening,

I recently purchased a Qnap QSW-M2116P-2T2S 2.5g/10g POE+ switch. Based on some information found at https://www.reddit.com/r/homelab/comments/p4czkr I determined the QNAP's documents were wrong about the rear RJ45 management port. QNAP had it listed as a 1gbps Ethernet port, it is actually a RS232 serial com port. When hooked up to a usb --> RJ45 console Cisco Rollover cable, a login prompt appears at 115200 baud, 8N1, no flow control. The router web page credentials gained access to a simple shell with basic cisco switch type commands.

After some experiemention I discovered that this router is also openwrt, as the device mentioned in the posted link above, and was able to break into RedBoot, which I am not familiar with. This unfortunatly is were I got stuck. RedBoot is set to loop reset so the only way to stop loadnig the switch software is to turn off the script loading using 'fconfig'. Once done, RedBoot still loop resets, and with each reset any applied settings done previously seems to drop. This limits the amount of experimentation. What I would like to do is break into the linux loading process after RedBoot loads the kernal, thus gaining me access to a linux shell, logs, and network info. Can anyone provide some information, help, or point me in the correct direction?
 
  • Like
Reactions: tamuin