#NullconBerlin2025 | Unlock hidden Superpowers in MediaTek Wi-Fi Chips by Daniel and Edoardo
About this talk
This talk covers the reverse engineering of MediaTek Wi-Fi chips, which are commonly used in a variety of devices, including smartphones, routers, and IoT devices. The speakers, Daniel Wegemer and Edoardo Mantovani, delve into the inner workings of MediaTek's firmware on the NDS32 architecture, addressing complexities such as undocumented hardware peripherals and CRC32 integrity checks. They share their innovative techniques for dumping protected ROMs and demonstrate how to unlock advanced features like raw I/Q data streaming and Channel State Information. Additionally, they present a collection of open-source tools designed to facilitate further research and development in Wi-Fi security and custom firmware for the community.
More from this event
See all 16 talks →
#NullconBerlin2025 | Panel: Industrial Systems In The Crosshairs: What It Really Takes To Defend OT
51:53
#NullconBerlin2025 | Stealing All macOS Sensitive Info with a Single Vulnerability by Koh
29:22
#NullconBerlin2025 | Derandomizing Kernel Object Locations w Software Hardware-Induced Side Channels
37:23
#NullconBerlin2025 | Your MCP Server Executes Commands - But From Whom? by Simcha Kosman
35:03