logo

A dive into the Rockchip Bootloader

ID: 9f823378-dcbb-5440-b20d-a6a7d0f386d9

STIX ID: report--9f823378-dcbb-5440-b20d-a6a7d0f386d9

Feed Name: Pen Test Partners Blog

Date Published: 2025-02-26

Date Updated: 2026-03-26

Author: David Lodge

...
...

This report provides a technical overview of Rockchip MCU boot stages (PPL/BootROM, SPL/idbloader or miniloader, and OS bootloader), how to enter and leverage MaskROM mode, and how to upload ddrplug/usbplug to communicate via the rockusb protocol for tasks such as reading/writing flash and dumping RAM. It demonstrates packet structure examples, a high-level method for reversing usbplug with Ghidra, and compares tooling (xrock, rkflashtool, rkdeveloptool, upgrade_tool, SocToolkit), concluding that while these mechanisms enable firmware access and data extraction, they do not by themselves represent a significant security risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.