Reverse-engineering writeup for a generic Chinese motorcycle CarPlay/Android Auto display with built-in dual-camera DVR — sold under "BOSSNEY" / "M553" / "REAKO SOUND" / no-name on AliExpress, and at least a dozen sibling brands. The goal is enabling split-screen simultaneous preview of both cameras (the stock launcher only shows one at a time even though both record concurrently).
Yes if you:
- Have a similar device (Allwinner F133-B + Melis 4.0 + SK1.4 SDK platform — Aoocci C3/C7/BX, CPMC X6/B7/Z55B, ricoel C5/C7, CarpodGo, Linkifun MT11A, Carpuride, almost any unbranded F133 motorcycle CarPlay unit) and want a head-start on RE.
- Want to see how to defeat PAIRIP DRM on a real-world Android app via surgical binary-AXML chunk deletion, without
apktool bmangling resources. - Want a worked example of Sunninglink's "SUN2024" cloud-API auth (sign scheme, endpoint inventory, brute-force results, why the cloud-OTA route is dead for our SKU).
- Are interested in the broader ODM-rebrand pool — there's a comparison of MStar Gemini / Mercury6, Allwinner F133 / IMAGEWTY, FullHan FH5701A firmware formats from competitor SKUs.
No if you:
- Want a one-click custom firmware. There isn't one — extracting M553's stock firmware needs hardware (SOIC8 clip + CH341a programmer on the SPI flash chip). Sessions 1–7 ruled out every software path.
- Want to flash this repo's contents to your device. Don't. Most of the firmware archives here are for different SoCs and would brick your unit.
| Path | Contents |
|---|---|
WRITEUP.md |
Full session-by-session narrative (sessions 1–7, 2026-04-29 → 2026-05-04). The "what we did and why" reference. |
NEXT_SESSION.md |
Tactical pickup plan: UART-pad hunt, then SOIC8 SPI-flash dump, then Ghidra on init.axf. |
RESEARCH_INDEX.md |
Deep-link map of every artifact. Read this first if you're looking for a specific file. |
samples/device_photos/ |
Vendor product photos (hero, mounting angles, home menu, TPMS UI, EQ UI, camera close-ups, REAKO-rebrand evidence). |
samples/probe_*/ |
UI screenshots from each phase of probing — debug-menu series (probe_phase3), factory-code attempts (probe_codes), 000000 Update Menu states (probe_update_menu), USB-C / SD-card probes. |
samples/cam_a/PICT0000.jpg, samples/cam_b/PICT0000.jpg |
One still per camera channel — proves both cameras output independent frames (camera A and camera B at the same timestamp 2026/04/29 13:40:22). |
research/sibling_apks/com.moto.amotocam/ |
The MotoNavi vendor app (base.apk + split_config.arm64_v8a.apk originals, plus base_full3_aligned.apk + split_aligned.apk — final patched + signed PAIRIP-bypassed installable). All AXML/drawable patcher scripts under scripts/. findings.md is the primary RE writeup. |
research/sibling_apks/com.{lg,ligo,xy}.*/ |
8 sibling motorcycle/dashcam apps for diff-mining (Roadcam V1+V3 SDK, Astro/dhc/dkomine/qrdash/superdash/tcam/aroadcamai). Each has findings.md or strings.txt. |
research/sibling_firmware/ |
Competitor firmware archives — ricoel C5/C7 (MStar Gemini), CPMC X6/B7/Z55B (Allwinner LiveSuit + MStar M6), Aoocci C4 (FullHan FH5701A). All publicly redistributed from vendor download pages. |
research/aoocci_c3plus_firmware/c3plus.img |
Aoocci C3 Plus stock firmware (Allwinner IMAGEWTY, 17 MB) — closest publicly-available F133 image. |
research/b5300_re/B5300-reverse-engineering/ |
Git submodule pointing at dan-os/B5300-reverse-engineering — toolchain (Melis MINFS unpacker, unpack.sh, repack.sh, flash.sh) + sample SK1.4 SDK firmwares unpacked. Run git submodule update --init after cloning to fetch. |
procedures/ |
Reproducible probe procedures (currently just 01-system-slot-probe.md — SD-card OTA scan timing). |
To clone with everything:
git clone --recurse-submodules https://github.com/fuho/moto-display-reNote: vendor APKs (originals + patched) and competitor firmware archives total ~600 MB. They're vendor-distributed binaries we obtained through normal purchase / vendor download pages, mirrored here for diff-mining and to make the writeup self-contained. RE for interoperability is a normal practice; if any vendor objects, they can email me.
Privacy: strings that would identify the personal environment — home Wi-Fi SSID, LAN IP, throwaway Mailinator handle, captured cloud-account access token — are replaced with placeholders (
<HOME_WIFI>,10.X.X.X, etc.) in every committed text file. The only password you'll find is the WPA-PSK12345678for the M553's own Wi-Fi AP, which is a vendor hardcode shared across this entire device family — not a personal credential.
5" landscape touchscreen (1024×600), waterproof bezel, handlebar mount, two bullet cameras, 2 wireless TPMS sensors, 64 GB microSD bundled.
| Field | Value | How we know |
|---|---|---|
| SoC | Allwinner F133-B (RISC-V C906, 64 MB DDR2 SiP) | apps/init.axf symbol set in B5300 sample matches; 64 MB confirmed by debug-menu Memory Info |
| OS | Melis 4.0 RTOS (Allwinner proprietary) | Boot log structure on B5300 sample, MINFS rootfs, init.axf ELF format |
| Launcher | SK1.4-8168V8.5-LMA-2511111456 |
Setup → Version screen (samples/probe_phase3/screenshots/500.jpg) |
| MCU FW | SK_02_20251104-1159 |
Same Version screen — secondary microcontroller bridges F133 to power/buttons/cameras |
| BT MAC | 41:42:00:00:1E:16 (LAA random per power-cycle) |
Version screen + BT advertising packets |
| BT_SET | BT_20250617_1557 (dual-BT firmware: phone + helmet intercom simultaneously) |
Version screen |
| Display | 1024×600 IPS, MIPI-DSI panel, Goodix touch | Native screenshot resolution + B5300 boot log analog |
| Wi-Fi MAC OUI | 5C:8E:8B (Realtek) |
ARP probe — confirms separate Wi-Fi/BT module (F133-B has no integrated wireless) |
| Camera topology | Topology B (independent simultaneous capture) | Both DVR slot folders DCIMA/ DCIMB receive aligned MJPEG clips at 1m/2m/5m intervals |
| Camera bridge | TechPoint TP2804 multi-channel analog video decoder | init.axf strings in B5300 sample reference tp2804; CSI lanes + AHD inputs |
| DVR ASIC | Generalplus | MJPEG codec, separate from F133 video pipeline |
| USB-C | Power-only | Phase 4 probe — no enumeration in HOST or SLAVE mode, even with debug toggle |
Entry path: Setup → Factory Set → Input Password.
| Code | Effect | Status |
|---|---|---|
112345 |
Debug Mode (memory/screenshot/USB/touch/network/panel test) | confirmed |
123579 |
Self-Test (自检) — diagnostic mode |
confirmed |
230762 |
Interface Select (界面选择) — UI / launcher skin chooser |
confirmed |
001106 |
Silent state change — dismisses keypad on Factory Set page | confirmed |
000000 |
Update Menu — exposes MCU OTA path; tap button searches SD for update file | confirmed |
112233 |
rejected (INVALID) on this build | tried |
113266 |
rejected (INVALID) on this build — B5300 "Factory" code, so M553 has a customized Config.ini |
tried |
The two rejected codes are documented in dan-os/B5300-reverse-engineering's apps/Config.ini as logoPassword=112233 / factoryPaswword=113266 (preserves the vendor's typo "Paswword"). They're configurable per-build, which is how we proved BOSSNEY customized the same SK1.4 SDK rather than rolling a different platform.
- Power connector: 4-pin, only 2 go to battery (12V + GND). The remaining 2 are very likely K1 / K2 momentary button inputs for installer-wired handlebar buttons (debug menu shows
K1:0 / K2:0counters with no physical button on the unit). - Two microSD slots, one each side. DVR slot (DCIMA/DCIMB MJPEG via Generalplus). System slot (USB-C side) is firmware-writable but passive on boot — used by the
000000Update Menu. - No physical UART exposed externally, but B5300 has TX at 500k baud on a board pad. Best non-invasive next step is hunting through screw holes or seam.
- The SPI flash chip (likely
EN25QH128A/cFeon QH128A16 MB SOIC-8) is the only known firmware extraction route. CH341a programmer + flashrom + SOIC8 clip.
The investigation went through 7 sessions, each ruling out a class of approaches. The detailed log is in WRITEUP.md. Here's the map:
- Phase 1 — what does the device expose? USB-C → nothing (power-only). Wi-Fi AP → all 17+ probed TCP ports return RST when in CarPlay/AA mode. SD-card filenames → no auto-flash trigger. Conclusion: the device is hermetic from the outside.
- Phase 2 — frida-unpack a sibling app.
com.lg.aroadcams"Roadcam" was packed but not PAIRIP-protected.frida-dexdump -U -f com.lg.aroadcamsgave us the full Allwinner V1 + V3 IPCAM SDK — 8742 classes, the entire HTTP CGI vocabulary used by F133 dashcams. This established the "language" of?custom=1&cmd=NNNNURLs. Re-probing M553 with this vocabulary still returned RST → the SDK isn't running on M553 in any operating mode. - Phase 3 — Bluetooth pairing capture. Captured the BT handover from the phone's Wireless Link mode. Extracted the WPA-PSK
12345678(hardcoded, same on every unit). Joined M553's Wi-Fi as a client, re-probed all known V1/V3 endpoints. Still RST. Conclusion: M553 never runs the V1/V3 server stack — the AP is just a CarPlay/AA passthrough. - Phase 4 — defeat MotoNavi (the vendor app).
com.moto.amotocamis the universal companion app for the entire F133 motorcycle CarPlay segment. It's PAIRIP-DRM'd. Builtaxml_delete_pairip.pythat surgically removes the<activity>and<provider>chunks forcom.pairip.licensecheckfrom the binary AndroidManifest, without runningapktool b(which silently manglesresources.arsc). Got the app running on stock Android. - Phase 5 — Sunninglink cloud API. With MotoNavi running and HTTP Toolkit MITM intercepting (after an
android:debuggable="true"AXML patch to make user CAs trusted), reverse-engineered the entire Sunninglink backend: 32 endpoints, the request signing schemesign = md5("SUN2024" + ts + uuid).lower(), the_8567deviceInfo string format (8 semicolon-separated fields parsed byFirmwareInfo.getByString()). Filed_8567brute-force attempts againstapp.sunninglink.com:9412/iotcam-api-server/firmwareUpgrade/checkUpdate— every variant returneddata:null. ThenbindDevicereturned10201 mac does not exist. M553's MAC is not in Sunninglink's pre-provisioned DB. The BOSSNEY supply chain didn't register units with the cloud. Cloud OTA is hard-closed. - Phase 6 — sibling firmware diff-mining. Collected and binwalked competitor firmware (ricoel C5/C7 MStar Gemini, CPMC Z55B MStar M6, CPMC X6/B7 Allwinner LiveSuit, Aoocci C4 FullHan, Aoocci C3 Plus IMAGEWTY) hoping for a structurally similar M553 image. None match — different SoCs, different OEM customization, different display panels.
- Phase 7 — definitive platform ID. Found
dan-os/B5300-reverse-engineering: Allwinner F133-B + Melis 4.0 + SK1.4 SDK with full toolchain (MINFS unpacker, sample firmwares). Boot log + symbol set + Config.ini structure all match M553. Pinned the platform conclusively. Located the dual-camera control surface inapps/init.axf(RISC-V ELF, 2 MB):cameraSwitch1Gpio,cameraSwitch2Gpio,CAvinInterface_SetAvChannel,CAvinCtrl_Open/Close,tp2804. Split-screen preview is achievable as a software patch toinit.axf.
- ✅ Platform definitively identified. Allwinner F133-B + Melis 4.0 RTOS + SK1.4 SDK + BOSSNEY-customized
Config.ini. Same family asdan-os/B5300. - ✅ Dual-camera control surface located in
init.axf. Symbols + driver are present; modifying camera switching logic to drive both channels into framebuffer regions for compositing is the path to split-screen preview. - ✅ MotoNavi (
com.moto.amotocam) fully RE'd. PAIRIP DRM defeated, TLS pinning bypassed, all 32 cloud endpoints documented,_8567parser reverse-engineered. - ❌ Cloud OTA path is dead for M553 —
bindDevicereturns10201 mac does not exist. The BOSSNEY supply chain didn't register units with Sunninglink. - ❌ Wi-Fi AP serves no DVR HTTP API in any operating mode. All 17+ probed TCP ports return RST. The V1/V3 SDK is in the launcher binary's siblings but not running on M553.
- ❌ USB-C is power-only. D+/D− are not wired to the F133 USB controller. The "USB Mode HOST/SLAVE" debug toggle is vestigial.
- ❌ The
000000Update Menu exposes the MCU OTA path (UART1 to the MCU), not the application firmware. Even with a perfect ISPBOOT.BIN we can't flash the launcher via SD card. ⚠️ Stock M553 firmware is not published anywhere. Only B5300 / F1026 samples exist publicly; those have a different display panel and different OEM customization (different boot logo, different brand strings, different camera GPIO assignments). Hardware extraction (SOIC8 clip on the SPI flash) is the only remaining route.
cd research/sibling_apks/com.moto.amotocam
# Originals (vendor-distributed)
ls base.apk split_config.arm64_v8a.apk
# Final patched + signed installable
ls base_full3_aligned.apk split_aligned.apk
adb install-multiple -r base_full3_aligned.apk split_aligned.apk
# Or rebuild from scratch:
bash scripts/build_patched_apk.shThe script chains: axml_delete_pairip.py (removes PAIRIP <activity>/<provider>), axml_add_debuggable.py (sets android:debuggable="true" so user CAs are trusted at runtime), axml_export_activity.py (exposes activities to adb am start), drawable_patch.py (repoints missing drawable refs after the manifest edits), apktool rebuild + classes8.dex steal, zipalign, apksigner.
See NEXT_SESSION.md. Concrete first move: hunt for a UART TX pad through screw holes / seam without opening the case — confirm 500k baud boot log matches B5300. If that's reachable, we've cross-validated the platform without committing to disassembly. Otherwise, open the case → SOIC8 clip on the SPI flash chip → CH341a + flashrom dump → unpack via the B5300 toolchain → diff init.axf against the SK1.4 sample → patch in Ghidra (RV32 LE).
MIT for the scripts and writeups in this repository. Vendor APKs and firmware archives included in research/ are vendor-copyrighted; mirrored here for non-commercial reverse-engineering, interoperability research, and security analysis only. If you're a vendor and want something removed, email me.
dan-os/B5300-reverse-engineering— same SK platform family (added here as a submodule)usr-sse2/lindenis-v833-RTOS-melis-4.0— Melis 4.0 source mirrorcarplaymotorcycle.com/pages/cpmc-support-center— CPMC firmware downloads (multi-SoC)aoocci.com/pages/motorcycle-support— Aoocci firmware index (mostly Allwinner)store.ricoel.com/software/— MotoPlay Lite firmware4pda.to/forum/index.php?showtopic=1059544— Russian forum thread on a similar F133 unit

