Introduction #
SO today, the 18th of August i had a customer i needed to help again. You might remmeber me talking about the fact i finally found a job. SO the customer was located near the City center and he ahd some help needed with his thunderbird mail. I helped him and afterwards i came across an Action store and as usual, i always go look inside to see if there are some nice things i can buy/new products. Thats where i found a new lamp in the lighting section of the store. It was a smart standing floorlamp by the brand LSC (Action’s own housebrand which in reality is just Electrocirkel BV celling Tuya powered smart gear what the Actionm sells under the LSC brand). Because it was a new product and to me it looked nice and interesting, i bought it. 17.95 euro lighter i walked out the store and went back home.
Back home i decided that i wnated to explore it and see if i could flash opensource firmware on it to free it from its cloud prison and also to make it more secure and private as the ‘S’ in IOT stands for security and the ‘P’ for privacy (The joke being that there is no ‘S’ or ‘P’ in the word IOT and thus there is no Privacy or Security when it comes to general IOT devices). I dont know what wifi module is inside but i am guessing its one of those newer tuya modules, with the Beken chips (Eg: cb2s, wb2s, cbu, etc etc) as the ESP based modules (eg Tywe3s, Tywe2s, Tywe1s, etc etc) are End off life by TUYA in favor of the newer beken powered modules. This also will mean that i probably cant install WLED or Esphome on it as those are built on the ESP chips/platform and espressif’s IDF Framework (Based on FreeRTOS).
Some pictures of the Product Below. #
SO below i put some pictures of the product’s outside and looks.


Pictures of the Unboxing. #





And below a picture of the full assembled Led Tube. Its quite long! The box says its 130cm with base attached and base is 11cm high, so 130-11 is around 120cm.

Pictures of it Powered on. #
Below a picture of it powered on. Its kinda bright! Box says 90 Lumen. And the box says that in the base there is a Normal analog leds while in the tube there is a strip of Adressable RGBIC leds. It also comes with a remote. It really does look nice!



Time for teardown. #
Okay lets not waste more time and lets take it apart! So I now have to find a way to Open up the device’s base to get to its circuitboard. SO i think the screws are under the Black foam on the bottom of the base. I Tried to remove it but i ended up ruining it fully, so i then decided to go hayewire and rip off all that foam which was a pain in the arse and i kind of regret having just pulled and destroyed it, but oh well, i can always maybe buy new sticky foam pads, but now we do have some screws.


Undoing those 3 screws and it can be opened! As you can see, we get a look at the PCB. Also there is a heavy metal weight in the Base as so it does not tip over easily.



Undoing some more screws and we get to see the PCB. I Did have to desolder the microphone as its wires where preventing the PCB from coming out. And we can see the PCB

Tuya Wifi Module #
Okay so its opened and we can see the PCB. Now i spot a white smaller module thats soldered on the board. Hmm, this seems like a new module as i never seen this one before. Its atleast not any of the CB2L/CB2S/WB2s/CBU modules i kmnow really well… Doing some research on the model number thats on it T1-U-HL, reveals its a Tuya made Wifi and Bluetooth Low Energy (BLE) Combination module. And it does contain a beken chip, but not the general/typical BK7231xx series but rather another beast, the bk7238. Seems its a more powerfull chip that uses Beken’s own in-house design and is a more modern, moder powerfull, more efficient platform. I used This website to see the comparison between the 2. Reading a bit more, it seems like the bk7238 is also supported by Openbeken, great! But before delving into that custom firmware, lets first try to get a copy of the stock firmware and also see if it has some usefull stuff inside. SO lets first continue our exploration.
Exploring it further. Also software wise. #
So time to explore the insides a bit deeper.
UART #
So on the PCB there is a pair of UART pads and actually 2 times. UART1 and UART2. I think UART2 is debug output off the firmware and UART1 is for programming. I hooked up to UART2 And UART1 but first lets see if UART2 is indeed the firmware’s debug output and see if we can get some boot output/logs. I did not have a picture for this as i did it off-camera, but i hooked up a FT4232h USB to UART converter board to UART2 on the PCB of the device and indeed, we get some output!
Bootlog Out-of-box #
V: T1_2.0.0
REG:cpsr spsr r13 r14
SVC:000000d3 00000010 00401c1c 000033a0
IRQ:000000d2 00000010 00401e0c 9ba6a070
FIR:000000d1 00000010 00401ffc 02a82a8c
ST:00000000
__read_manage_block: mag->blockid=255, id=0, mag->state=255.
__read_manage_block: mag->magic=0xffffffff, rescrc=0x00000000, mag->crc32=0xffffffff.
__read_manage_block: mag->blockid=255, id=1, mag->state=255.
__read_manage_block: mag->magic=0xffffffff, rescrc=0x00000000, mag->crc32=0xffffffff.
_judge_ota_info checkerr0:1, checkerr1:1
init err -5
jump to:0x10000
prvHeapInit-start addr:0x417120, size:167648
[Flash]id:0x852015
bk_timer_init exit
sctrl_sta_ps_init
**********tuya_upgrade_main need upgrade? [255]**********
cset:0 0 0 0
[FUNC]rwnxl_init
IP Rev: 90d35d1
[bk]ttkl_ethernetif_init
tkxhernetif_init
[FUNC]ilNC]intc_init
ntc_init
[FUNC]calibration_main
gpio_level=1,txpwr_state=15
device_id=0x220[01-01 00:00:00 ty D][41cd][tal_thread.c:209] Thread:sys_timer Exec Start. Set to Running Stat 0x41cd18
6ty D][41c[01-01 00:00:00 ty I][4d][tal_thread.c:185] th184][tal_thread.c:185] tread_create name:sys_tihread_create name:sys_tmer,stackDepth:4096,totimer,stackDepth:4096,toalstackDepth:12288,priotalstackDepth:12288,pririty:5
ority:5
[01-01 00:00:00 ty I][4184][tal_thread.c:185] thread_create name:wq_system,stackDepth:5120,totalstackDepth:17408,priority:3
[01-01 00:00:00 ty I][4184][tal_thread.c:185] thread_create name:wq_highpri,stackDepth:4096,totalstackDepth:21504,priority:4
[01-01 00:00:00 ty D][4184][tuya_svc_netmgr_linkage.c:86] link[9] is registered [0]
[01-01 00:00:00 ty D][4184][tuya_svc_netmgr_linkage.c:86] link[2] is registered [1]
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:0
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:1
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:2
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:3
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:4
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:5
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:6
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:7
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:8
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:9
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:58] init watchdog, interval: 60
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:161] update type:7,period:20
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:491] watch_dog_interval:60, monitor_detect_interval:600
[01-01 00:00:00 ty D][4206][tal_thread.c:209] Thread:health_monitor Exec Start. Set to Running Stat 0x4206a8
[01-01 00:00:00 ty D][41f5][tal_thread.c:209] Thread:wq_highpri Exec Start. Set to Running Stat 0x41f578
[01-01 00:00:00 ty I][4184][tal_thread.c:185] thread_create name:health_monitor,stackDepth:2048,totalstackDepth:23552,priority:5
[01-01 00:00:00 ty I][4184][mqc_app.c:493] mqc app init ...
[01-01 00:00:00 ty D][4184][mqc_app.c:112] mq_pro:5 cnt:1
[01-01 00:00:00 ty D][4184][mqc_app.c:112] mq_pro:31 cnt:2
[01-01 00:00:00 ty D][4184][tuya_svc_online_log.c:291] svc online log init success
[01-01 00:00:00 ty E][4184][log_seq.c:930] logseq empty
[01-01 00:00:00 ty D][4184][tuya_ws_db.c:466] init fs. Path: null
[01-01 00:00:00 ty D][4184][kv_storge.c:46] *****************kvs_init.
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:206] protected init. addr:0x001e4000
[01-01 00:00:00 ty N][4184][simple_flash_protected.c:87] init protected data length 730 wr_cnt 19
[01-01 00:00:00 ty N][4184][simple_flash.c:447] key_addr: 0x1f5000 block_sz 4096
[01-01 00:00:00 ty N][4184][simple_flash.c:533] get key:
0xf5 0xe2 0x2d 0xa9 0x46 0x19 0x30 0xba 0xbb 0x2c 0x62 0x5e 0xf7 0x93 0xc7 0x46
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:216] protected verify begin
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:231] check [rcs.active][55]
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:231] check [kv.ccode.avtive][2]
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:231] check [gw_bi][328]
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:231] check [gw_wsm][201]
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:243] protected verify end
[01-01 00:00:00 ty D][4184][simple_flash.c:877] begin try update kv version
calibration_main over
flash txpwr table:0xf
dif g and n20 ID in flash:4
read txpwr tab from flash success
calibrate low value:[474]
calibrate high value:[8eb]
temp in flash is:260
lpf_i & q in flash is:128, 128
found flash XTAL:52
use xtal:52
xtal_cali:52
--init_xtal = 52
[FUNC]ps_init
[FUNC]func_init_extended OVER!!!
start_type:0
Version:
app_init finished
[01-01 00:00:00 ty E][418d][api_lib.c:227] LWIP_NETCONN_THREAD_SEM_FREE:not find thread sem
[01-01 00:00:00 ty D][4184][simple_flash.c:884] pre kv version is 2
[01-01 00:00:00 ty D][4184][simple_flash.c:1185] 111 k=1 i=3 1
[01-01 00:00:00 ty N][4184][tuya_tls.c:913] uni_random_init...
[01-01 00:00:00 ty N][4184][tuya_tls.c:354] tuya_tls_rand_init ok!
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:343] protected read [gw_bi]
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:387] protected read ret:0 length:328
[01-01 00:00:00 ty D][4184][ws_db_gw.c:148] gw_bi read ret:0
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:343] protected read [gw_wsm]
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:387] protected read ret:0 length:201
[01-01 00:00:00 ty D][4184][ws_db_gw.c:257] gw_wsm read ret:0
[01-01 00:00:00 ty N][4184][tuya_svc_devos.c:366] gw_cntl->gw_wsm.stat:1
[01-01 00:00:00 ty D][4184][ws_db_gw.c:374] gw_di read ret:0
[01-01 00:00:00 ty D][4184][ws_db_gw.c:457] gw_ai read ret:0
[01-01 00:00:00 ty D][4184][uni_network.c:184] cache dns [http://a1-eu.lifeaiot.com/d.json]<->[18.199.123.50]
[01-01 00:00:00 ty D][4184][uni_network.c:184] cache dns [https://a3-eu.lifeaiot.com/d.json]<->[18.198.62.99]
[01-01 00:00:00 ty D][4184][uni_network.c:184] cache dns [m1-eu.lifeaiot.com:1883]<->[3.69.125.150]
[01-01 00:00:00 ty D][4184][uni_network.c:184] cache dns [m3-eu.lifeaiot.com:8883]<->[3.65.184.32]
[01-01 00:00:00 ty D][4184][uni_network.c:184] cache dns [baal.tuyaeu.com:443]<->[18.193.97.90]
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:343] protected read [rcs.active]
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:387] protected read ret:0 length:55
[01-01 00:00:00 ty D][4184][tuya_cert_manager.c:467] tls_ca_cnt:0 and parse:0
[01-01 00:00:00 ty D][4184][tuya_cert_manager.c:919] psk key was 3.0
[01-01 00:00:00 ty D][4184][tuya_cert_manager.c:898] psk_id len:49
[01-01 00:00:00 ty D][4184][tuya_cert_manager.c:899] psk_id_arr 49 <0x420fb0>
03 1c 7a e3 6a b0 1f bb 86 f7 37 8e cf 61 a9 a6 56 40 ec 2f ff 95 60 8f 2c 30 de 36 c3 79 cd 0c 0b 77 64 9e 13 36 dd bc 3a fd 95 62 ee 10 ba a9 2f
[01-01 00:00:00 ty D][4184][tuya_cert_manager.c:952] pub was 1,use mf psk key
[01-01 00:00:00 ty D][4184][tuya_cert_manager.c:1059] cert manager init
[01-01 01:00:00 ty N][4184][tuya_app_main.c:254] sdk_info:< TuyaOS V:3.11.11 BS:40.00_PT:2.3_LAN:3.5_CAD:1.0.5_CD:1.0.0 >
< BUILD AT:2025_03_05_20_01_36 BY ci_manage FOR tuyaos-iot AT T1 >
IOT DEFS < WIFI_GW:1 DEBUG:1 KV_FILE:0 LITTLE_END:1 SL:0 OPERAT[01-01 01:00:00 ty N][4184][tuya_app_main.c:255] name:scw_oyvz9kqyvcl7b45n:1.2.1
[01-01 01:00:00 ty N][4184][tuya_app_main.c:256] firmware compiled at Jan 6 2026 14:23:15
[01-01 01:00:00 ty N][4184][tuya_app_main.c:257] system reset reason:[0]
*******************************tuya_os_adapt_set_cpu_lp_mode,en = 1, mode = 0
pmu_release_wakelock(PMU_OS)
mcu_ps_init 0
bk_wlan_mcu_ps_mode_enable()
*******************************tuya_os_adapt_set_cpu_lp_mode,en = 0, mode = 0
mcu_ps_exit 0
bk_wlan_mcu_ps_mode_disable()
bk_ps_mode_disable
temp_code:31 - adc_code:246 - adc_trend:[13]:260->[14]:250
init_xtal:52, delta:-1, last_xtal:52
[01-01 01:00:01 ty N][4184][tuya_app_main.c:217] mf_init successfully
[01-01 01:00:01 ty N][4184][tuya_iot_wifi_api.c:310] wifi soc init. pid:oyvz9kqyvcl7b45n firmwarekey:NULL ver:1.2.1
[01-01 01:00:01 ty N][4184][tuya_iot_wifi_api.c:209] sw ver: 1.2.1
[01-01 01:00:01 ty N][4184][tuya_wifi_link.c:86] start wifi link params validate, nc_tp:10 md:0
[01-01 01:00:01 ty N][4184][tuya_wifi_link.c:108] gw_wsm.nc_tp:10
[01-01 01:00:01 ty N][4184][tuya_wifi_link.c:109] gw_wsm.md:0
[01-01 01:00:01 ty N][4184][tuya_svc_devos.c:594] Last reset reason: 0
[01-01 01:00:01 ty N][4184][tuya_svc_devos.c:423] gw_cntl->gw_if.abi:0 input:0
[01-01 01:00:01 ty N][4184][tuya_svc_devos.c:424] gw_cntl->gw_if.product_key:oyvz9kqyvcl7b45n, input:oyvz9kqyvcl7b45n
[01-01 01:00:01 ty N][4184][tuya_svc_devos.c:425] gw_cntl->gw_if.tp:0, input:0
[01-01 01:00:01 ty N][4184][tuya_svc_devos.c:627] enter success_proc
[01-01 01:00:01 ty N][4184][tuya_svc_devos.c:630] serial_no:20f1b2d6314b
[01-01 01:00:01 ty N][41f5][tuya_wifi_link.c:636] kv has ccode NL
rw_ieee80211_set_country code:
code: EU
channel: 1 - 13
mode: MANUAL
bk_wlan cca opened
ap net info ip: 192.168.176.1, mask: 255.255.255.0, gw: 192.168.176.1
ssid:SmartLife-314B, key:, channel: 6
[saap]MM_RESET_REQ
[bk]tx_txdesc_flush
[saap]ME_CONFIG_REQ
sending broadcast_deauth:[saap]ME_CHAN_CONFIG_RE5Q
net_wlan_remove_neti[saap]MM_START_REQ
f vif_idx invalid
tkl_wifi_scan_ap
[csa]csa_in_[sa_sta]MM_RESET_REQ
[bk]tx_txdesc_flush
p_flush
[sa_sta]ME_CONFIGhapd_intf_add_vif,type:_type:3, s:0, id:0
3, [sa_sta]ME_CHAN_CONFIG_s
apm start with vif:0
REQ
------beacon_int_set:100 TU
set_active param 0
[msg]APM_STOP_CFM
update_ongoing_1_bcn_update
[sa_sta]MM_STvif_idx:0, ch_idx:0, bcAidx:0, bcmc_idx:1
mc_idx:1
sending broadcast_deauth:5
hapd_intf_ioctl:939
hapd_intf_ioctl:939
hapd_intf_ioctl:939
hapd_intf_ioctl:939
update_ongoing_1_bcn_update
netif_is_added: 0x40d018
netif_is_added: 0x40cfd0
net_wlan_add_netif already exist!, vif_idx:0
mac 20:f1:b2:d6:31:4a
net_wlan_add_netif done!, vif_idx:0
sizeof(wpa_supplicuap_ip_start
configuaith IP)ring uap(with IP)hapd_intf_add_vif,typdef netif is sta
sendieth:ng b5
wpa_dInit
r
hapd_intf_ioctl:939
hapd_intf_ioctl:939
hapd_intf_ioctl:939
hapd_i[01-01 01:00:01 ty N][4n01:00:01 ty N][41f5][t1f5][tuya_wifi_status.cuya_wifi_status.c:167] :167] cur stat:13 0xc2bcur stat:13 0xc2bed --ed -->>
[01-01 01:00:0>13 -->>
hapd_intf_io1:939
[01-01 01:00:01 c01 ty N][41f5][tuya_wity N][41f5][tuya_wifi_sfi_status.c:173] reporttatus.c:173] report wif wifi netstat[13] to cali netstat[13] to callbalback ck -->>
hapd_in -->>
-tf_ioctl:939---
netif_is_added: 0x40d--wf_sta 13
[01-01 01:041f5][tuya_wifi_reset.00:01 tyc:410] timer st N][41f5][tuya_wifi_reseated, short t.c:410] titimer:0x0, long timer:0mer stated, short timerx0
netif_is_added: 0x4:0x0, long timer:0x0
0cfd0
net_wlan_add_neti[01-01 01:00:01 ty N][4f N][41f5][tuya_bt_link1f5][tuya_bt_link.c:64] .c:64] bt startup attr:bt startup attr:ff
[01ftype:0 oyvz9kqyvcl7b45-01 01:00:01 ty Nn
mac]
initial BLE...
ble mac:20-f1-b2-d6-31-4c
rwip_heap_env addr:0x430e18 size:1432
rwip_heap_msg addr:0x4313b8 size:4248
rwip_heap_non_ret addr:0x432458 size:668
xvr_reg_init
tx_pwr_idx:28
enter normal mode
r normal mode
net_wlan_add_netif done!, vif_idx:1
[01-01 01:00:01 ty N][41f5][tuya_bwpa_supplicant_req_scanle_svc.c:
Setting scan1[01-01 01:00:01 ty N][[01 ty N][41f5][tuya_bl41f5][tuya_ble_sdk.c:44e_sdk.c:444] start ble 4] start ble adv!!!
adv!!!
wpa_supplicant_sc[01-01 01:00:01 ty N][4wlan_sta_scan_once triea tries count: 0
wpa_su1spplicant_scan 868
wpa_drv_scan
wpa_send_scan_req
ht in scan
scan_start_req_handler, chan_cnt 13
scan_start_req_handler
wpa_driver_scan_start_cb
[01-01 01:00:01 ty E][41f5][tuya_svc_timer_task.c:1383] read timer_full_key failed
[01-01 01:00:01 ty N][41f5][tuya_svc_devos.c:278] __devos_init_evt success
RSSI: 00:31:92:28:08:46 -49 -> -48
temp_code:33 - adc_code:242 - adc_trend:[14]:250->[15]:240
init_xtal:52, delta:-2, last_xtal:51
scanu_confirm: status 0, upload_cnt 49, recv_cnt 49, time 1334779us, result 9
wpa_driver_scan_cb
Scan completed in 1.328000 seconds
wpa_get_scan_rst:9
nc_type 10
[01-01 01:00:02 ty N][41f5][ble_gap.c:2505] Start Adv
nx_hw_error
phy_interface_underrun count=0
[01-01 01:00:02 ty N][41f5][tuya_ble_svc.c:1439] ble adv updated
[01-01 01:00:02 ty E][41f5][wifi_netcfg_frame_transporter.c:325] timer is not run,wait
phy_error count=0
phy_error count=1Bootlog When the device is fully setup and connected to the App. #
V: T1_2.0.0
REG:cpsr spsr r13 r14
SVC:000000d3 00000010 00401c1c 000033a0
IRQ:000000d2 00000010 00401e0c 9ba6a072
FIR:000000d1 00000010 00401ffc 02282b8c
ST:00000000
__read_manage_block: mag->blockid=255, id=0, mag->state=255.
__read_manage_block: mag->magic=0xffffffff, rescrc=0x00000000, mag->crc32=0xffffffff.
__read_manage_block: mag->blockid=255, id=1, mag->state=255.
__read_manage_block: mag->magic=0xffffffff, rescrc=0x00000000, mag->crc32=0xffffffff.
_judge_ota_info checkerr0:1, checkerr1:1
init err -5
jump to:0x10000
prvHeap
V: T1_2.0.0
REG:cpsr spsr r13 r14
SVC:000000d3 00000010 00401c1c 000033a0
IRQ:000000d2 00000010 00401e0c 9fa6a072
FIR:000000d1 00000010 00401ffc 02a82a8c
ST:00000000Í
}µ
+ÖVÖ%ëkÖKj
µò±½¥õªªbJõbj
µòÑ
Ñõªªrj¤ôõ%
}µ
¹
}±½éj
µòj
¥õ±ÍÉõÂÁbj
µòÉÍê¹jRôõ%
}µ
¹
}±½éj
µò±½¥õªªbJõbj
µòÑ
Ñõªªrj¤ôõ%
}µ
¹
}±½éj
µòj
¥õ±ÍÉõÂÁbj
µòÉÍê¹jRô¥«}½Ñ
}¥¹½¡ÉÉÁÒb¡ÉÉÅÒj¤Ë+R..HKMC
µump to:0x10000
prvHeapInit
V: T1_2.0.0
REG:cpsr spsr r13 r14
SVC:000000d3 00000010 00401c1c 000033a0
IRQ:000000d2 00000010 00401e0c 9fa6a072
FIR:000000d1 00000010 00401ffc 02a82a8c
ST:00000000
__read_manage_block:_XVɱ½¥õªªbJõbj
µòÑ
Ñõªªrj¤ôõ%
}µ
¹
}±½éj
µòj
¥õ±ÍÉõÂÁbj
µòÉÍê¹jRôõ%
}µ
¹
}±½éj
µò±½¥õªªbJõbj
µòÑ
Ñõªªrj¤ôõ%
}µ
¹
}±½éj
µòj
¥õ±ÍÉõÂÁbj
µòÉÍê¹jRô¥«}½Ñ
}¥¹½¡ÉÉÁÒb¡ÉÉÅÒj¤Ë+R..HKMC
µump to:0x10000
prvHeapInit
V: T1_2.0.0
REG:cpsr spsr r13 r14
SVC:000000d3 00000010 00401c1c 000033a0
IRQ:000000d2 00000010 00401e0c 9ba6a076
FIR:000000d1 00000010 00401ffc 02a82a8c
ST:00000000
__read_manage_block: mag->blockid=255, id=0, mag->state=255.
__read_manage_block: mag->magic=0xffffffff, rescrc=0x00000000, mag->crc32=0xffffffff.
__read_manage_block: mag->blockid=255, id=1, mag->state=255.
__read_manage_block: mag->magic=0xffffffff, rescrc=0x00000000, mag->crc32=0xffffffff.
_judge_ota_info checkerr0:1, checkerr1:1
init err -5
jump to:0x10000
prvHeapInit-start addr:0x417120, size:167648
[Flash]id:0x852015
bk_timer_init exit
sctrl_sta_ps_init
**********tuya_upgrade_main need upgrade? [255]**********
cset:0 0 0 0
[FUNC]rwnxl_init
IP Rev: 90d35d1
[bk]ttkl_ethernetif_init
tkxhernetif_init
[FUNC]ilNC]intc_init
ntc_init
[FUNC]calibration_main
gpio_level=1,txpwr_state=15
device_id=0x22[01-01 00:00:00 ty D][41cd][tal_thread.c:209] Thread:sys_timer Exec Start. Set to Running Stat 0x41cd18
0 ty D][41c[01-01 00:00:00 ty I][4d][tal_thread.c:185] th184][tal_thread.c:185] read_create name:sys_timthread_create name:sys_er,stackDepth:4096,totatimer,stackDepth:4096,tlstackDepth:12288,priorotalstackDepth:12288,prity:5
iority:5
[01-01 00:00:00 ty I][4184][tal_thread.c:185] thread_create name:wq_system,stackDepth:5120,totalstackDepth:17408,priority:3
[01-01 00:00:00 ty I][4184][tal_thread.c:185] thread_create name:wq_highpri,stackDepth:4096,totalstackDepth:21504,priority:4
[01-01 00:00:00 ty D][4184][tuya_svc_netmgr_linkage.c:86] link[9] is registered [0]
[01-01 00:00:00 ty D][4184][tuya_svc_netmgr_linkage.c:86] link[2] is registered [1]
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:0
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:1
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:2
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:3
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:4
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:5
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:6
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:7
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:8
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:114] add new node,type:9
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:58] init watchdog, interval: 60
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:161] update type:7,period:20
[01-01 00:00:00 ty D][4184][tuya_devos_health.c:491] watch_dog_interval:60, monitor_detect_interval:600
[01-01 00:00:00 ty D][4206][tal_thread.c:209] Thread:health_monitor Exec Start. Set to Running Stat 0x4206a8
[01-01 00:00:00 ty D][41f5][tal_thread.c:209] Thread:wq_highpri Exec Start. Set to Running Stat 0x41f578
[01-01 00:00:00 ty I][4184][tal_thread.c:185] thread_create name:health_monitor,stackDepth:2048,totalstackDepth:23552,priority:5
[01-01 00:00:00 ty I][4184][mqc_app.c:493] mqc app init ...
[01-01 00:00:00 ty D][4184][mqc_app.c:112] mq_pro:5 cnt:1
[01-01 00:00:00 ty D][4184][mqc_app.c:112] mq_pro:31 cnt:2
[01-01 00:00:00 ty D][4184][tuya_svc_online_log.c:291] svc online log init success
[01-01 00:00:00 ty E][4184][log_seq.c:930] logseq empty
[01-01 00:00:00 ty D][4184][tuya_ws_db.c:466] init fs. Path: null
[01-01 00:00:00 ty D][4184][kv_storge.c:46] *****************kvs_init.
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:206] protected init. addr:0x001e4000
[01-01 00:00:00 ty N][4184][simple_flash_protected.c:87] init protected data length 736 wr_cnt 22
[01-01 00:00:00 ty N][4184][simple_flash.c:447] key_addr: 0x1f5000 block_sz 4096
[01-01 00:00:00 ty N][4184][simple_flash.c:533] get key:
0xf5 0xe2 0x2d 0xa9 0x46 0x19 0x30 0xba 0xbb 0x2c 0x62 0x5e 0xf7 0x93 0xc7 0x46
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:216] protected verify begin
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:231] check [kv.ccode.avtive][2]
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:231] check [gw_bi][328]
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:231] check [rcs.active][55]
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:231] check [gw_wsm][207]
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:243] protected verify end
[01-01 00:00:00 ty D][4184][simple_flash.c:877] begin try update kv version
calibration_main over
flash txpwr table:0xf
dif g and n20 ID in flash:4
read txpwr tab from flash success
calibrate low value:[474]
calibrate high value:[8eb]
temp in flash is:260
lpf_i & q in flash is:128, 128
found flash XTAL:52
use xtal:52
xtal_cali:52
--init_xtal = 52
[FUNC]ps_init
[FUNC]func_init_extended OVER!!!
start_type:0
Version:
app_init finished
[01-01 00:00:00 ty E][418d][api_lib.c:227] LWIP_NETCONN_THREAD_SEM_FREE:not find thread sem
[01-01 00:00:00 ty D][4184][simple_flash.c:884] pre kv version is 2
[01-01 00:00:00 ty D][4184][simple_flash.c:1185] 111 k=5 i=9 6
[01-01 00:00:00 ty N][4184][tuya_tls.c:913] uni_random_init...
[01-01 00:00:00 ty N][4184][tuya_tls.c:354] tuya_tls_rand_init ok!
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:343] protected read [gw_bi]
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:387] protected read ret:0 length:328
[01-01 00:00:00 ty D][4184][ws_db_gw.c:148] gw_bi read ret:0
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:343] protected read [gw_wsm]
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:387] protected read ret:0 length:207
[01-01 00:00:00 ty D][4184][ws_db_gw.c:257] gw_wsm read ret:0
[01-01 00:00:00 ty N][4184][tuya_svc_devos.c:366] gw_cntl->gw_wsm.stat:2
[01-01 00:00:00 ty D][4184][ws_db_gw.c:374] gw_di read ret:0
[01-01 00:00:00 ty D][4184][ws_db_gw.c:457] gw_ai read ret:0
[01-01 00:00:00 ty D][4184][uni_network.c:184] cache dns [http://a1-eu.lifeaiot.com/d.json]<->[18.192.81.114]
[01-01 00:00:00 ty D][4184][uni_network.c:184] cache dns [https://a3-eu.lifeaiot.com/d.json]<->[18.158.227.228]
[01-01 00:00:00 ty D][4184][uni_network.c:184] cache dns [m1-eu.lifeaiot.com:1883]<->[18.156.58.194]
[01-01 00:00:00 ty D][4184][uni_network.c:184] cache dns [m3-eu.lifeaiot.com:8883]<->[3.65.184.32]
[01-01 00:00:00 ty D][4184][uni_network.c:184] cache dns [baal.tuyaeu.com:443]<->[3.124.173.10]
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:343] protected read [rcs.active]
[01-01 00:00:00 ty D][4184][simple_flash_protected.c:387] protected read ret:0 length:55
[01-01 00:00:00 ty D][4184][tuya_cert_manager.c:467] tls_ca_cnt:0 and parse:0
[01-01 00:00:00 ty D][4184][tuya_cert_manager.c:919] psk key was 3.0
[01-01 00:00:00 ty D][4184][tuya_cert_manager.c:898] psk_id len:49
[01-01 00:00:00 ty D][4184][tuya_cert_manager.c:899] psk_id_arr 49 <0x420fb0>
03 3c ac 10 c8 30 13 45 0a e8 f1 14 aa 8e f8 a9 d6 40 ec 2f ff 95 60 8f 2c 30 de 36 c3 79 cd 0c 0b 77 64 9e 13 36 dd bc 3a fd 95 62 ee 10 ba a9 2f
[01-01 00:00:00 ty D][4184][tuya_cert_manager.c:952] pub was 1,use mf psk key
[01-01 00:00:00 ty D][4184][tuya_cert_manager.c:1059] cert manager init
[01-01 01:00:00 ty D][4184][tuya_wifi_connect.c:285] set station.
[01-01 01:00:00 ty D][4184][simple_flash_protected.c:343] protected read [kv.ccode.avtive]
[01-01 01:00:00 ty D][4184][simple_flash_protected.c:387] protected read ret:0 length:2
[01-01 01:00:00 ty N][4184][tuya_wifi_link.c:636] kv has ccode NL
[01-01 01:00:00 ty D][4184][tal_wifi.c:738] set ccode to env EU
rw_ieee80211_set_country code:
code: EU
channel: 1 - 13
mode: MANUAL
bk_wlan cca opened
[01-01 01:00:00 ty N][4184][tuya_wifi_connect.c:88] fast connect mode:0
[01-01 01:00:00 ty D][4184][tal_wifi_reconnet.c:152] wifi auto reconn ssid YOUR_WIFI_SSID
[01-01 01:00:00 ty D][4184][tuya_wifi_connect.c:80] ap_info_v2 read success
[01-01 01:00:00 ty N][4184][tal_wifi_reconnet.c:170] fast connect
!! tkl_wifi_station_fast_connect
>>> mhdr_set_station_status_cb
>>> _wifi_station_status_cb 0
wlan_clear_fast_connect_info
>>> mhdr_set_station_status 0
>>> _wifi_station_status_cb 0
[sa_sta]MM_RESET_REQ
[bk]tx_txdesc_flush
[sa_sta]ME_CONFIG_REQ
[sa_sta]ME_CHAN_CONFIG_REQ
[sa_sta]MM_START_REQ
fast_connect
sizeof(wpa_supplicant)=928
hapd_intf_add_vif,type:2, s:0, id:0
wpa_dInit
hapd_intf_ioctl:939
hapd_intf_ioctl:939
hapd_intf_ioctl:939
hapd_intf_ioctl:939
hapd_intf_ioctl:939
hapd_intf_ioctl:939
netif_is_added: 0x40d018
netif_is_added: 0x40cfd0
net_wlan_add_netif already exist!, vif_idx:0
mac 20:f1:b2:d6:31:4b
net_wlan_add_netif done!, vif_idx:0
me_mgmt_tx chan no avail
cipher2security 2 2 16 16
cipher2security 2 2 16 16
wpa_supplicant_connect
Cancel[01-01 01:00:00 ty Nchan avail
lail
][4184][tuya_wifi_status.c:167]wpa_driver_associate: a cur stat:5 0x0 -->>
uth_alg 0x1
>>> mhdr_set_station_status 3
>>> _wifi_station_status_cb 3
[01-01 01:00:00 tyfound scan rst rssi -54 < -50
bssid 00:31:92:28:08:46, cap_info 0x1031, BI 100, ssid YOUR_WIFI_SSID
sm_auth_send:1
8:46, cap_info 0x1031, BI 100, ssid REDACTEDsm_auth_handler
ht in assoc req
_IOT
[01-01 01:00:00 ty D][4184][tuya_wifi_connect.c:298] wf fast connect succ.
[01-01 01:00:00 ty sm_assoc_rsp_handler
rc_init: station_id=0 format_mod=2 pre_type=0 short_gi=1 max_bw=0
rc_init: nss_max=0 mcs_max=7 r_idx_min=0 r_idx_max=3 no_samples=10
---------SM_CONNECT_IND_ok
Not associated Nay - Delay processing processing of received of received EAPOL frame EAPOL frame (state=ASSO(state=ASSOCIATING bssiCIATING bssid=00:00:00:d=00:00:00:00:00:00 )
00:00:00 )
[01-01 01:00:00 ty N][4184][tuya_app_main.c:255] name:scwCancelling scan request_oyvz9kqyvcl7b45n:1.2.1
[01-01 01:00:00 ty N][4184][tuya_app_main.cWPA: TK fbbe1070404785e:256] firmware compiled1777d17371698b59d
at Jan 6 2026 14:23:15
[01-01 01:00:00 ty N][4184][tuya_app_main.c:257] system reset reason:[0]
hapd_intf_add_key CCMP
add sta_mgmt_get_sta
sta:0, vif:0, key:0
hapd_intf_add_key:322
sta_mgmt_add_key
add hw key idx:24
WPA: GTK 08e85889b6124ca49b20cf1c05debd3b
hapd_intf_add_key CCMP
add is_broadcast_e
new ie: 0 : 33 30 39 45 6c 65 63 74 72 6f 6e 69 63 73 5f 49 4f 54
new ie: 1 : 82 84 8b 96 c 12 18 24
new ie: 3 : 4
new ie: 2d : ee 11 1b ff ff 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0
new ie: 30 : 1 0 0 f ac 4 1 0 0 f ac 4 2 0 0 f ac 2 0 f ac 4 0 0
ther_addr
sta:255, vif:0, key:1
add hw key idx:1
ctrl_port_hdl:1
me_set_ps_disable:943 0 0 0 0 3 0
>>> mhdr_set_station_status 10
>>> _wifi_station_status_cb 10
WLAN_EVENT_CONNECTED
sta_ip_start
configuring mlan(with DHCPc)writed fci to flash ssid=YOUR_WIFI_SSID
*******************************tuya_os_adapt_set_cpu_lp_mode,en = 1, mode = 0
pmu_release_wakelock(PMU_OS)
mcu_ps_init 0
bk_wlan_mcu_ps_mode_enable()
*******************************tuya_os_adapt_set_cpu_lp_mode,en = 0, mode = 0
mcu_ps_exit 0
bk_wlan_mcu_ps_mode_disable()
bk_ps_mode_disable
------wf_sta 5
temp_code:30 - adc_code:249 - adc_trend:[13]:260->[14]:250
init_xtal:52, delta:-1, last_xtal:52
[01-01 01:00:01 ty N][4184][tuya_app_main.c:217] mf_init successfully
[01-01 01:00:01 ty N][4184][tuya_iot_wifi_api.c:310] wifi soc init. pid:oyvz9kqyvcl7b45n firmwarekey:NULL ver:1.2.1
[01-01 01:00:01 ty N][4184][tuya_iot_wifi_api.c:209] sw ver: 1.2.1
[01-01 01:00:01 ty N][4184][tuya_wifi_link.c:86] start wifi link params validate, nc_tp:9 md:3
[01-01 01:00:01 ty N][4184][tuya_wifi_link.c:108] gw_wsm.nc_tp:9
[01-01 01:00:01 ty N][4184][tuya_wifi_link.c:109] gw_wsm.md:3
[01-01 01:00:01 ty N][4184][tip_addr: d30a0a0a
>>> mhdr_set_station_status 11
>>> _wifi_station_status_cb 11
WFE_CONNECTED 11
1
[01-01 01:00:01 ty N][41f5][tal_wifi_reconnet.c:278] wifi status changed to 0, stat: 1
[01-01 01:00:01 ty E][41f5][tuya_svc_mqtt_client.c:1497] handle null
[01-01 01:00:01 ty N][4184][tuya_svc_devos.c:423] gw_cntl->gw_if.abi:0 input:0
[01-01 01:00:01 ty N][4184][tuya_svc_devos.c:424] gw_cntl->gw_if.product_key:oyvz9kqyvcl7b45n, input:oyvz9kqyvcl7b45n
[01-01 01:00:01 ty N][4184][tuya_svc_devos.c:425] gw_cntl->gw_if.tp:0, input:0
[01-01 01:00:01 ty N][41f5][tuya_svc_mqtt_client.c:180] [mqtts://m3-eu.lifeaiot.com:8883] mqtt state change 0 -> 1
[01-01 01:00:01 ty N][4184][tuya_svc_devos.c:627] enter success_proc
[01-01 01:00:01 ty N][4236][tuya_svc_mqtt_client.c:943] connect to mqtt broker mqtts://m3-eu.lifeaiot.com:8883 port 8883
[01-01 01:00:01 ty N][4236][tuya_svc_mqtt_client.c:955] mqtt client ip:10.10.10.211, link-tp:2
[01-01 01:00:01 ty N][4184][tuya_svc_devos.c:630] serial_no:20f1b2d6314b
[01-01 01:00:01 ty N][41f5][tuya_wifi_status.c:167] cur stat:6 0xc2bed -->>
[01-01 01:00:01 ty N][41f5][tuya_wifi_status.c:169] wifi netstat changed to:6 -->>
[01-01 01:00:01 ty N][41f5][tuya_wifi_status.c:173] report wifi netstat[6] to callback -->>
------wf_sta 6
[01-01 01:00:01 ty N][41f5][tuya_bt_link.c:64] bt startup attr:ff
[01-01 01:00:01 ty N][41f5][tuya_ble_svc.c:1257] upd product_id type:0 oyvz9kqyvcl7b45n
nc_type 4
initial BLE...
ble mac:20-f1-b2-d6-31-4c
rwip_heap_env addr:0x4327b8 size:1432
rwip_heap_msg addr:0x432d58 size:4248
rwip_heap_non_ret addr:0x433df8 size:668
xvr_reg_init
tx_pwr_idx:28
enter normal mode
[01-01 01:00:01 ty N][41f5][tuya_ble_svc.c:1352] ty bt sdk init success finish
[01-01 01:00:01 ty E][41f5][tuya_svc_timer_task.c:1383] read timer_full_key failed
[01-01 01:00:01 ty N][41f5][tuya_svc_devos.c:278] __devos_init_evt success
[01-01 01:00:01 ty N][41f5][tuya_svc_devos.c:106] already bind
[01-01 01:00:01 ty N][41f5][tuya_svc_devos_daemons.c:314] Main Module: v1.0.0 (1.2.1)
[01-01 01:00:01 ty E][41f5][astro_timer.c:326] astro timer read fail:-6
[01-01 01:00:01 ty E][41f5][astro_timer.c:861] read fail:-6
[01-01 01:00:01 ty N][41f5][tuya_wifi_status.c:167] cur stat:6 0xc2bed -->>
[01-01 01:00:01 ty N][41f5][ble_gap.c:2505] Start Adv
[01-01 01:00:01 ty N][41f5][tuya_ble_svc.c:1439] ble adv updated
[01-01 01:00:01 ty N][4236][tuya_svc_mqtt_client.c:992] setup mqtt transporter success
[01-01 01:00:01 ty N][4236][tuya_svc_mqtt_client.c:180] [mqtts://m3-eu.lifeaiot.com:8883] mqtt state change 1 -> 2
[01-01 01:00:01 ty N][4236][tuya_svc_mqtt_client.c:1018] send mqtt connect success
[01-01 01:00:01 ty N][4236][tuya_svc_mqtt_client.c:180] [mqtts://m3-eu.lifeaiot.com:8883] mqtt state change 2 -> 3
[01-01 01:00:01 ty N][4236][tuya_svc_mqtt_client.c:1048] mqtt connect success
[01-01 01:00:01 ty N][4236][tuya_svc_mqtt_client.c:180] [mqtts://m3-eu.lifeaiot.com:8883] mqtt state change 3 -> 4
[01-01 01:00:01 ty N][4236][tuya_svc_mqtt_client.c:787] mqtt topics cnt 1
[01-01 01:00:01 ty N][4236][tuya_svc_mqtt_client.c:801] send mqtt subscribe success
[01-01 01:00:01 ty N][4236][tuya_svc_mqtt_client.c:180] [mqtts://m3-eu.lifeaiot.com:8883] mqtt state change 4 -> 5
[01-01 01:00:01 ty N][4236][tuya_svc_mqtt_client.c:1089] mqtt subscribe success
[01-01 01:00:01 ty N][4236][tuya_svc_mqtt_client.c:180] [mqtts://m3-eu.lifeaiot.com:8883] mqtt state change 5 -> 6
[01-01 01:00:01 ty N][41f5][tuya_wifi_status.c:167] cur stat:7 0xc2bed -->>
[01-01 01:00:01 ty N][41f5][tuya_wifi_status.c:169] wifi netstat changed to:7 -->>
[01-01 01:00:01 ty N][41f5][tuya_wifi_status.c:173] report wifi netstat[7] to callback -->>
------wf_sta 7
[01-01 01:00:01 ty E][41f5][smart_frame.c:625] devid:NULL dparr[10]:34 not find
tkl_wifi_get_connected_ap_info
[08-18 13:03:39 ty N][4236][tuya_svc_online_log.c:253] timeout,delete uf local log
[08-18 13:03:39 ty E][41e3][tuya_bt_link.c:160] tuya_ble_save_beacon_key err -1
[08-18 13:03:39 ty N][41cd][tuya_svc_lan.c:973] udp ip: 10.10.10.211
free_mem_size: 41416
[08-18 13:03:41 ty N][41cd][tuya_ble_svc.c:1449] ble_sdk_send skip, serv stat:0, conn stat:4
free_mem_size: 41416
[08-18 13:03:44 ty E][41e3][uf_flash_file_app.c:338] uf_open netcfg_log err 8
free_mem_size: 41416
free_mem_size: 41416
free_mem_size: 41384
[08-18 13:03:50 ty N][41e3][tuya_devos_utils.c:109] reset dp rate rule finish.
free_mem_size: 41240
free_mem_size: 41240
[08-18 13:03:54 ty E][41e3][tuya_svc_upgrade.c:903] result null
free_mem_size: 41096
free_mem_size: 41096
free_mem_size: 41096
free_mem_size: 41096
free_mem_size: 41096
free_mem_size: 41096
free_mem_size: 41096
free_mem_size: 41096
free_mem_size: 41096
free_mem_size: 41096What is TuyaOS? #
So the device is based on TuyaOS. This is a framework/SDK provided by Tuya for making IOT smart appliances. It is used to build a smart IOT appliance and its firmware. It can be considered as an application stack that sits ontop of an existing OS base/framework and it handles the SMart IOT and app control stuff and talking to Tuya’s servers. It can deployed on Embedded Linux or FreeRTOS. This Base OS layer is often provided by the chip/SOC vendor. In smart IP cameras its deployed ontop of Embedded Linux which then is often provided by the SOC vendor like Ingenic/Anyka/Fullhan or any other vendor. In our case it sits ontop of FreeRTOS as the bk7238 is a microcontroller and lacks the power and components needed for a Linux kernel. And its powerd by FreeRTOS provided by the Beken SDK. And this is the firmware that powers it. You can also see some mentions of task and thats very typical off an RTOS as an RTOS runs Tasks. And you can also see that its TuyaOS version 3.11.11.
Backing up stock firmware. #
So now lets move on to backing up and getting a copy of the stock firmware so in case we want to, we can revert it back to factory stock firmware. To do this there is a handy tool called “Openbeken flasher” which allows us to (VIA the UART1) interact with a lot of Beken chips and reprogram/read/erase them. First i hooked up wires to UART1.

SO now open up the Openbeken flasher software.

Serial UART port: simply is the Serial port that you hooked the device up to on your PC. Select chip type simply is the chip type, so for us this needs to be bk7238 but here its set as default to bk7231. Thats all we need for now. Then you can click the button Firmware backup (read) only. This will read the firmware off the chip and dump it into a file. When clicked, a dialog pops up asking you to name the file. I put in a name here and then started it. It asked me to reset the chip so i did this by holding the pad on the PCB labled as reset RST to GND. This restarts the chip and then the software can put it into programming mode and read the current firmware. Afterwards it should pop open another window where you can see the current configuration thats loaded on the chip in JSON format. Sadly for me it did not seem to contain much usefull info about GPIO pins and such while in some cases it will have GPIOs configured in this configuration but seems not the case for my device… Maybe they hardcoded it or the TuyaOS is a lot newer so this program gets confused or whatevrr i dont know, but thats not a dealbreaker and we will figure it out some other way. NAyways, we atleast have a dump of the firmware!
Hacking it. #
SO now i have a copy of the stock firmware we can move on to flashing OpenBEKEN on it and freeing it from the cloud, but first what is OpenBEKEN?
What is OpenBeken? #
OpenBeken is a Opensource (FOSS) project that aims to create opensource cloud-free MQTT enabled firmware replacement for the newer beken and realtek chips found in the newer tuya products and the newer tuya modules. Its comparable to Esphome/Tasmota, but instead of only supporting ESP chips it also supports others. In short it makes opensource firmware that makes it so the device can be fully operated locally without any data being sent to china, america, russia, israel or any other country (Trying to not get politic). And it uses the same MQTT (Message Queuing Telemetry Transport) as esphome and tasmota and wled.
Just like the mentioned Esphome, Tasmota and WLED, its also based on FreeRTOS, a real time operating system platform that supports a lot of popular microcontrollers and cpu cores and its the heart of the ESP IDF (for esp chips. Also used in Arduino ESP Board support and wled/esphome) and also the beken chips their SDK (Software Development Kit). A RTOS can be thought of (in very simple kind of bad example/explanation terms) as a more fancier arduino program. As an RTOS often is used to perform a handfull of tasks or do 1 task and do it well and no other fuss. Unlike embedded Linux, it really is application specific/tailored, just like an arduino program to drive a display only drives the display and nothing else. As mentioned before, ontop of such OS base is always an Application stack and this Its an alternative project that makes that application stack but without any of the Tuya or cloud vendor’s magic sauce/stuff and thus makes it completely cloud-free and secure and private.
Flashing OpenBEKEN #
So time to flash openbeken on it. We will use the same Openbeken flasher software as we used to dump the device. But now we first click on the “Select firmware” box which will prompt us to automatically download firmware file for the bk7238. After thats done we cna click on either backup and flash new or do firmware write (no backup. Because i alr made a backup i clicked the write only option. Then reset the chip again and it will start writing openbeken on it. After thats done, reboot it by unplugging and replugging power and disconnecvting the UART programmer (as that could power it through the UART pins). After that it should come up as a OpenBK7238 or something wifi network in your wifi networks list. This is the Initial configuration portal that Openbeken ships with that allows setting up the device if it has no wifi or setup yet. Connect to that network and go to the Management page (should open automatically). Congratulations, you just got to the OpenBEKEN Web Interface!
As you can see, the device emits no light, but thats because its not configured for anything and has no GPIO pins set. Below is a picture of how the WEB Interface looks.

Simply click the blue ‘Config’ button. This opens a whole list of configurable options. CLick on ‘Configure WIFI & Web’. This opens a new menu where you can set your wifi and password.

You can either click ‘scan local networks’ which scans for nearby networks. You can also manually type in your wifi name (SSID) and password. You can even set a Web interface password so you cant access the web interface unless you type in the password but i wont and will leave it open for now. Click Apply and then the device will apply settings and reboot. After that, look into your router’s list to see what IP the device has. Then go to that IP address. Or you can look into the logs to see what IP the device mentions. This should then lead you back to the device’s web interface. Simply Click “Launch Web Application” which opens the Wbe application in which you can start configuring stuff.

Configruing OpenBEKEN. #
SO now is the tedious challenge of configruing the GPIO’s. Now in that Web Application i started toggeling random GPIO’s until i got lights showing (Probably wrong thing to do but its easy to do trial and error). I will first make the base leds work and then move onto the Adressable lights. I know Channel 1=Red, 2=Green, 3=Blue, 4=Coldwhite, 5=Warmwhite. Also after flipping random GPIO’s i eventually found out the table below:
| GPIO | Color |
|---|---|
| P8 | RED |
| P24 | GREEN |
| P9 | BLUE |
| P5 | warmwhite |
| P5 | Coldwhite |
As you can see warmwhite and coldwhite is both on the same GPIO, but they do something interesting. Now lets configure it in OpenBEKEN. So i configured the GPIO’s and set them to the values in the table below. So set the GPIO pin, mode/type and the channel. These channels correlate with the predefined hardcoded values in Openbeken for R, G, B, W.
| GPIO | Type | Channel |
|---|---|---|
| P8 | PWM | 1 |
| P24 | PWM | 2 |
| P9 | PWM | 3 |
| P5 | PWM | 5 |
By setting channel 5 for the White gpio, it allows controling both warmwhite and coldwhite. Next up is figuring out the remote GPIO and the Adressable leds gpio. After some searching i found that my leds could be Ws2812 amd thus use the sm16703 driver in OpenBEKEN and also thus often use gpio16. I tried it and it works!
Final OpenBeken config. #
I did some further mesing about and below is the final config i came up with. Unfortunately i have not found a way to control both ledstrips individually in openbeken (might be a software limitation or something not implemented), but yeah now you can control the main channel which is the led tube but you need to use mqtt commands to drive the base strip.
{
"vendor": "Tuya",
"bDetailed": "0",
"name": "Action LSC Smart Floor Lamp",
"model": "3221699",
"chip": "BK7238",
"board": "T1-U-HL",
"flags": "-2004451200",
"keywords": [
"TODO",
"TODO",
"TODO"
],
"pins": {
"8": "PWM;1",
"9": "PWM;3",
"16": "SM16703P_DIN;0",
"23": "IRRecv;0",
"24": "PWM;2",
"26": "PWM;5"
},
"command": "backlog startDriver SM16703P; SM16703P_Init 97 GRB; startDriver PixelAnim;",
"image": "https://obrazki.elektroda.pl/YOUR_IMAGE.jpg",
"wiki": "https://www.elektroda.com/rtvforum/Flashing_OpenBEKEN-software_on_the_new_Action-LSC_Floor-Lamp.html"
}The JSON should contain everything thats needed. I did not yet implement the IR functionality as i am too busy with work and other stuff, that i cant try and capture the 24x IR commands and then add an eventhandler for all, but feel free to take a peek at it yourself. Also i did not yet get the Microphone working as when i wnated to solder it back, i managed to rip off one of the microphone pads and i simply dont need the microphone functionality anyways.
Ending #
So thats it for now. I am quite proud what i managed to do in 1 day work but its sadly not as polished/complete as i had hoped. And its a bummer that OpenBeken does not allow controlling PWM channels separately from the RGBIC channel, but maybe because these hybrid lamps are quite new that they have not implemented it yet. I also had some similar trouble with WLED so maybe its not a priority as most lamps and lights are single light and thus use 1 strip instead of mixed rgbic and analog. But maybe that changes in the future. I Also posted on the Elektroda forum but i have to wait for it to be approved/checked.