DS-KV6113-WPE1(C) - Password Reset - All methods failed - Need help

Hello @trempa92,

I saw that you successfully helped recover the DS-KV6113-WPE1(C) in this thread.

I own a Hikvision DS-KB8113-IME1(B) that is stuck in a boot loop. Through UART I can access U-Boot, but <span>tftpboot</span> requests maintenance authentication with a challenge code and password.

I have proof of purchase and full physical access to the device. Would you be willing to help generate the authentication response for a fresh challenge from this model?

I have not posted or generated the challenge yet because it appears to be time-sensitive. If you can help, please let me know when you are available and I will send a fresh code by private message.

Thank you.
 
You dont need Debug access to flash firmware on it.

You stop boot with ctrl + u

Run tftp with firmware

set the device ip with setenv deviceIP and serverIP so they are in same subnet

Run command either "update" , "setenv update" , "setenv ';update'

Or if it ever prompts you for upgrade press B neither Y or N. This will give you HKWS shell
 
Thank you. Your method successfully triggered the TFTP transfer on my DS-KB8113-IME1(B).

I entered the U-Boot shell with b and ran update directly. The complete official firmware was downloaded successfully.

TFTP from server 192.0.0.128; our IP address is 192.0.0.64
Filename: digicap.dav
Load address: 0x1a00000
Bytes transferred: 24973824 (17d1200 hex)

However, the update then stopped with:

UPD error: invalid boot params!
digicap update failure.
U-Boot#

Running pboot gives:

ERROR [bsp_print_param-124]: invalid param info

The HDB is still readable with phdb and identifies:

PCB: DS-94516 (0x17134)
HDB: v2.0.0
PCB version: v1.0.0

The normal boot also reports:

ERROR [bsp_data_init-85]: Invalid bootparam info! ret=-2

The firmware is the official DS-KB8113-IME1(B) V2.2.60 build 231204 package.

The bootloader also lists this command:

nvt_update_all - To Update all-in-one image from memory address and size

I have not run that command because I do not know whether it is safe to use directly with digicap.dav.

Is there a safe way to reconstruct the boot parameters, or should another command be used after the firmware has been loaded into RAM?

Thank you again.