DS-KV6113-WPE1(C) - Password Reset - All methods failed - Need help

Hello @trempa92,

I saw that you successfully helped recover the DS-KV6113-WPE1(C) in this thread.

I own a Hikvision DS-KB8113-IME1(B) that is stuck in a boot loop. Through UART I can access U-Boot, but <span>tftpboot</span> requests maintenance authentication with a challenge code and password.

I have proof of purchase and full physical access to the device. Would you be willing to help generate the authentication response for a fresh challenge from this model?

I have not posted or generated the challenge yet because it appears to be time-sensitive. If you can help, please let me know when you are available and I will send a fresh code by private message.

Thank you.
 
You dont need Debug access to flash firmware on it.

You stop boot with ctrl + u

Run tftp with firmware

set the device ip with setenv deviceIP and serverIP so they are in same subnet

Run command either "update" , "setenv update" , "setenv ';update'

Or if it ever prompts you for upgrade press B neither Y or N. This will give you HKWS shell
 
  • Like
Reactions: vladmend
Thank you. Your method successfully triggered the TFTP transfer on my DS-KB8113-IME1(B).

I entered the U-Boot shell with b and ran update directly. The complete official firmware was downloaded successfully.

TFTP from server 192.0.0.128; our IP address is 192.0.0.64
Filename: digicap.dav
Load address: 0x1a00000
Bytes transferred: 24973824 (17d1200 hex)

However, the update then stopped with:

UPD error: invalid boot params!
digicap update failure.
U-Boot#

Running pboot gives:

ERROR [bsp_print_param-124]: invalid param info

The HDB is still readable with phdb and identifies:

PCB: DS-94516 (0x17134)
HDB: v2.0.0
PCB version: v1.0.0

The normal boot also reports:

ERROR [bsp_data_init-85]: Invalid bootparam info! ret=-2

The firmware is the official DS-KB8113-IME1(B) V2.2.60 build 231204 package.

The bootloader also lists this command:

nvt_update_all - To Update all-in-one image from memory address and size

I have not run that command because I do not know whether it is safe to use directly with digicap.dav.

Is there a safe way to reconstruct the boot parameters, or should another command be used after the firmware has been loaded into RAM?

Thank you again.
 
Nvt command asks for image file not dav archive. And image files arent publicly available. Only if you extract on working unit during runtime when its decrypted via psh
 
  • Like
Reactions: vladmend
Thank you, that explains why using nvt_update_all with the downloaded digicap.dav would be wrong. No write was performed because the command stopped at the authentication prompt.

I have already unpacked the official DAV and extracted its CramFS and LZ4/CPIO ramdisk, including psh, but the included bootloader/component files are clearly not a raw all-in-one image for nvt_update_all.

Could you please clarify:

  1. What is the usual filename or format expected by nvt_update_all on this Novatek platform?
  2. Where can that decrypted image be found or captured on a working unit during a firmware upgrade?
  3. Which psh command would be used to extract it?
  4. Would an image from an identical DS-KB8113-IME1(B), PCB DS-94516 / board ID 0x17134, be usable?
  5. Does the image contain device-specific boot parameters, MAC address, serial number or certificates that must not be cloned?
My unit still has a working U-Boot and HDB, but its boot parameters are invalid. My goal is to reconstruct only the damaged data and preserve all device-specific information.
 
Some questions are beyond my paygrade unfortunately.

Without doing exacly what you want its hard to tell

But in order to twinkle around files you need root access def
 
  • Like
Reactions: vladmend
I have acquired a second working unit of the same model. I will proceed carefully, starting with read-only inspection and backups. Once we have completed the tests, I will post the procedure and results here for anyone facing the same problem.

Thanks again!
 
I now have a second, fully working DS-KB8113-IME1(B) donor unit, running the same V2.2.60 build 231204 firmware.

Here is what we confirmed:

  • UART is externally accessible and works at 115200 8N1.
  • We can stop boot with Ctrl+U and enter U-Boot with B.
  • Read-only commands such as pboot, phdb and printenv work.
  • Commands such as md, cramfsload and nvt_boot trigger RSA challenge authentication:
enter auth
CAAAA...
Password:
  • The challenge changes on every attempt.
  • The working unit boots Linux normally.
  • SSH can be enabled through ISAPI and root accepts the current administrator password, but the interactive session is restricted to psh.
  • The psh Debug command also requests challenge/response authentication.
  • Non-interactive SSH commands, SFTP and the known stdin bypass do not work on this firmware.

Our goal is strictly read-only: obtain a backup of the donor flash or the decrypted runtime image, then use it to reconstruct the corrupted boot parameters of the original unit.

If you have access to the Hikvision challenge-response generator, could you generate the password for a live challenge from the psh Debug command?

Is the response valid only for that exact challenge/session? If so, we can coordinate in real time and keep the SSH/UART session open while waiting.

Once root access is obtained, I plan to inspect /proc/mtd and dump each MTD partition over the network, without modifying the donor.

Any recommended read-only command sequence would also be greatly appreciated.