TP-LINK TGR1900 (Google OnHub)
| abgn+ac (AC1750) | |
|---|---|
| Google OnHub Wireless Router | |
|
| |
| Wikipedia | TP-Link |
| WikiDevi.wi-cat.ru | TP-LINK TGR1900 (Google OnHub) |
| 3rd Party Firmware | |
| dd-wrt | Status Unknown |
| OpenWrt | Supported |
| Tomato any flavor | Incompatible |
| Gargoyle | Status Unknown |
| Platform | |
| Brand • Model • Rev | TP-LINK TGR1900 BLU (Google OnHub) |
| FCC ID | TE7TGR1900 |
| IC ID | 8853A-TGR1900 |
| Type | wireless router |
| CPU1 | Qualcomm IPQ8064 |
| CPU1 Type | ARMv7-A Cortex-A15 |
| CPU1 Speed | 1.4 GHz ( 2 cores ) |
| Flash1 Chip | Micron MTFC4GACAAAM-1MWT |
| Flash1 Size | 4 GiB 4,096 MiB <br />4,294,967,296 B <br />33,554,432 Kib <br />4,194,304 KiB <br />32,768 Mib <br /> (eMMC NAND) |
| Flash2 Chip | Micron N25Q064A |
| Flash2 Size | 8 MiB8,388,608 B <br />65,536 Kib <br />8,192 KiB <br />64 Mib <br />0.00781 GiB <br /> |
| RAM1 Size | 1 GiB 1,024 MiB <br />1,073,741,824 B <br />8,388,608 Kib <br />1,048,576 KiB <br />8,192 Mib <br /> |
| RAM1 Chip | Micron MT41K256M16HA-125:E x 2 |
| ETH chip1 | Qualcomm IPQ8064 |
| Switch | Qualcomm Atheros QCA8337 |
| Ethernet Port Count |
1-1GbE-WAN 4-1GbE-LAN |
| Wired Standard | IEEE 802.3i/3u/3ab |
|
802dot11 OUI: none specified | |
| Stock bootloader | Coreboot |
| Expansion IF types | USB 3.0 |
| USB ports | 1 |
| USB Hub Compatible | Untested |
| Power | 12 VDC, 3 A |
| Connector type | barrel |
| Serial Port (UART) | yes, (115200 8N1) |
| JTAG Port | no |
|
Flags: | |
|
Additional chips | |
| Other | |
|
| |
| 3rd Party Firmware Support |
OpenWrt • (List | Dev | DLs) |
| Retail | |
| Availability | End of Life |
| FCC approval date | 12 August 2015 |
| (Est.) initial retail price (in USD): | $200 |
| ASIN |
B013ALA9LA |
| Country of manuf | China |
| Radio 1 | |
| Chip1 | Qualcomm Atheros QCA9880 |
| Wireless interface OUI | none specified |
| Antenna Connector Type | U.FL |
| MIMO status | 3x3:3 |
| Wireless Standard | IEEE 802.11b/g/n |
| 802.11n | up to 450 Mbps |
| 802.11g | up to 54 Mbps |
| 802.11b | up to 11 Mbps |
| WiFi Operating Frequency | 2.4 GHz |
| Radio 2 | |
| Chip1 | Qualcomm Atheros QCA9880-BR4A |
| Wireless interface OUI | none specified |
| Antenna Connector Type | U.FL |
| MIMO status | 3x3:3 |
| Wireless Standard | IEEE 802.11a/n/ac |
| 802.11ac | up to 1300 Mbps |
| 802.11n | up to 450 Mbps |
| 802.11a | up to 54 Mbps |
| WiFi Operating Frequency | 5 GHz |
| Radio 3 | |
| Chip1 | Qualcomm Atheros QCA9882 |
| Wireless interface OUI | none specified |
| Antenna Connector Type | none specified |
| MIMO status | 1x1:1 |
| Wireless Standard | IEEE 802.11a/b/g/n/ac |
| WiFi Operating Frequency | 2.4 or 5 GHz |
For a list of all currently documented Qualcomm chipsets with specifications, see Qualcomm.
For a list of all currently documented Qualcomm Atheros (QCA) chipsets with specifications, see Qualcomm Atheros.
For a list of all currently documented TP-LINK devices with specifications, see TP-LINK.
Overview
"Model: TGR1900(BLU)(US) Ver:1.0", "1520" (05/2015),
- "02002" and "CA-F121" is silkscreened on the board.
This device was under short-term confidentiality, but that expired 02/05/2016 ⚠.
Links of Interest
- Product page (Google OnHub Router)
- Product page (TP-LINK TGR1900 OnHub Router)
Reviews
- CPU: Qualcomm IPQ8064 @1.4GHz
- Flash: 4GB + 8MB, RAM: 1GB (DDR3)
- Switch: Qualcomm Atheros QCA8337 (GbE)
- 2.4GHz Radio: Qualcomm Atheros QCA9880 (3x3 802.11abgn)
- - Skyworks SE2623L 2.4GHz power amp (x3)
- - Skyworks unidentified DPDT switch ("S81") (x3)
- - Skyworks SKY65971-11 2.4GHz 256QAM LNA (x3)
- 5GHz Radio: Qualcomm Atheros QCA9880 (3x3 802.11an/ac)
- - Skyworks SKY85405 5GHz Power amp (x3)
- - Skyworks SKY13438 6GHz DPDT switch (x3)
- - Skyworks SKY65981-11 5GHz 802.11ac LNA (x3)
- Monitor: Qualcomm Atheros QCA9882 (1x1 802.11abgn/ac)
- Bluetooth: Atheros AR3012 Bluetooth 4.0 SoC
- ZigBee: Silicon Labs EM3581 ZigBee/Thread SoC
- - Skyworks SKY66109-11 2.4GHz Front End Module
Teardown
- CPU: Qualcomm IPQ8064 @1.4GHz
- Dual-core (2x Krait 300)
- Flash: 8MB (SPI) + 4GB (eMMC)
- Micron N25Q064A (64Mb SPI flash)
- Micron MTFC4GACAAAM (4GB NAND flash)
- chip marked "M, 4ZA28JWA57, 7PYG" (4GB eMMC NAND)
- RAM: 1GB - 2x Micron MT41K256M16HA 512MB (256Mbx16)
- chip marked "M, 5DE77D9PXV, PGGL" (4Gb DDR3L SDRAM)
- WLAN: 2x Qualcomm Atheros QCA9880 (3T3R 802.11abgn/ac)
- Congestion-sensing radio: Qualcomm Atheros QCA9882 (1x1)
- Skyworks SKY2623L - 2.4GHz WLAN Power amplifier
- Skyworks SKY85405 - 5GHz WLAN Power amplifier
- Antenna: Dual band 2.4GHz and 5GHz 12-antenna array
- 6x 2.4GHz antennas (marked J211, J212, J221, J222, J231, J232)
- 6x 5GHz antennas (marked J511, J512, J521, J522, J531, J532)
- 1x congestion-sensing antenna (JS1)
- Bluetooth: Atheros AR3012-BL3D Bluetooth 4.0 SoC + antenna (JBT1)
- Infineon SLB9615 - Trusted Platform Module
- ZigBee: Silicon Labs EM3581 SoC Network Co-Processor + ant. (JZB1)
- Skyworks SKY66109 - 2.4GHz ZigBee/Smart Energy front-end module
- Switch: Qualcomm Atheros QCA8337 (1x WAN, 1x LAN)
- USB: 1x USB 3.0 port + Bluetooth 4.0
- LED: National Semiconductor LP5523 Programmable 9-output LED driver
- Ambient light sensor, Speaker 3W
Flashing
| NOTE: During configuration or flashing a device, the only things that should be hooked to the device is the computer and power. |
Flashing OpenWrt
| Since OpenWRT version 24.10, CPU target ipq806x has switched to DSA architecture. Hence upgrading from earlier versions to 24.10.x or later requires complete reset of all router configuration. |
Subtarget: chromium
Package architecture: arm_cortex-a15_neon-vfpv4
Supported Since Commit
Support started version: 23.05.0
Current supported version: 25.12.5
WLAN Hardware: 2x Qualcomm Atheros QCA9880, Qualcomm Atheros QCA9882
WLAN Comment: QCA9882 is 1x1 for monitoring, not regular use
Installation method(s):
see devicepage
Recovery method(s):
see devicepage
Comment:
Bluetooth 4.0, ZigBee, TPM 1.2, Speaker. 4GB eMMC
| git • >> |
|---|
ipq806x: Initial TP-Link and ASUS OnHub support
TP-Link and ASUS OnHub devices are very similar, sharing many of the
same characteristics and much of their Device Tree. They both run a
version of ChromeOS for their factory firmware, and so installation
instructions look very similar to Google Wifi [1].
Things I've tested, and are working:
* Ethernet
* WiFi (2.4 and 5 GHz)
* LEDs
* USB
* eMMC
* Serial console (if you wire it up yourself)
* 2x CPU
* Speaker
== Installation instructions summary ==
1. Flash *-factory.bin to a USB drive (e.g., with `dd`)
2. Insert USB drive, to boot OpenWrt from USB
3. Copy the same *-factory.bin over to device, and flash it to eMMC to
make OpenWrt permanent
== Developer mode, booting from USB (Step 2) ==
To enter Developer Mode and boot OpenWrt from a USB stick:
1. Unplug power
2. Gain access to the "developer switch" through the bottom of the
device
3. Hold down the "reset switch" (near the USB port / power plug)
4. Plug power back in
5. The LED on the device should turn white, then blink orange, then
red. Release the reset switch.
6. Insert USB drive with OpenWrt factory.bin
7. Press the hidden developer switch under the device to boot to USB;
you should see some activity lights (if you have any) on your USB
drive
8. Depending on your configuration, the router's LED(s) should come on.
You're now running OpenWrt off a USB stick.
These instructions are derived from:
https://www.exploitee.rs/index.php/Rooting_The_Google_OnHub#Enabling_%22Developer_Mode%22_on_the_OnHub
https://www.exploitee.rs/index.php/Asus_OnHub#Enabling_%22Developer_Mode%22_on_the_OnHub
~~Finding the developer switch:~~ for TP-Link, the developer switch is
on the bottom of the device, underneath some of the rubber padding and a
screw. For ASUS, remove the entire base, via 4 screws under the rubber
feet. See the Exploitee instructions for more info and photos.
== Making OpenWrt permanent (on eMMC) (Step 3) ==
Once you're running OpenWrt via USB:
1. Connect Ethernet to the LAN port; router's LAN address should be at
192.168.1.1
2. Connect another system to the router's LAN, and copy the factory.bin
image over, via SCP and SSH:
scp -O openwrt-ipq806x-chromium-tplink_onhub-squashfs-factory.bin root@192.168.1.1:
ssh root@192.168.1.1 -C "dd if=/dev/zero bs=512 seek=7552991 of=/dev/mmcblk0 count=33 && \
dd if=/root/openwrt-ipq806x-chromium-tplink_onhub-squashfs-factory.bin of=/dev/mmcblk0"
3. Reboot and remove the USB drive.
== Developer mode beep ==
Note that every time you boot the OnHub in developer mode, the device
will play a loud "beep" after a few seconds. This is described in the
Chromium docs [2], and is intended to make it clear that the device is
not running Google software. It is nontrivial to completely disable this
beep, although it's possible to "acknowledge" developer mode (and skip
the beep) by using a USB keyboard to press CTRL+D every time you boot.
[1] https://openwrt.org/toh/google/wifi
[2] https://chromium.googlesource.com/chromiumos/docs/+/HEAD/developer_mode.md
|
Pictures
- TP-LINK
- Embedded system/wireless router
- Embedded System Qualcomm
- Embedded System IPQ8064
- Qualcomm
- Embedded System ARMv7-A
- Embedded System Cortex-A15
- Embedded System Qualcomm Atheros
- Embedded System QCA8337
- Qualcomm Atheros
- OpenWrt Supported
- Embedded System QCA9880
- Has Mimo Status
- Embedded System IEEE 802.11b/g/n
- Embedded System QCA9880-BR4A
- Embedded System IEEE 802.11a/n/ac
- Embedded System QCA9882
- Embedded System IEEE 802.11a/b/g/n/ac
- Triple-Radio Wireless Embedded System
- Wireless Embedded System
- Tri-Band
- Embedded System
- English Documentation