Debricking NETGEAR r7500 (or r7800 / XR500) --> JTAG?

Hello,

I was wondering if anyone has any experience or info on enabling and using JTAG on a NETGEAR r7500 router?
On the PCB, there is a 20 pin header which looks exactly like an ARM 20pin JTAG connector. The voltages seem to match as well: 0V measured on the GND pins, 1.8V on the VCC and other data pins. I've soldered a header, and tried with two different JTAG adapters, but no device was found... I've heard that on some devices, it is necessary to solder an additional resistor to enable JTAG: might that be the case?
Similar information for r7500v2, r7800, xr450 or xr500 is welcomed as well, since they all use a similar CPU.

Before anyone asks, yes I really need JTAG (or any other "low-level" method) as I have accidentally made the bootloader unusable. If anybody wonders, here's how: I was "exploring" the device memory and this happened:

root@R7500:/# cat /proc/mtd
dev:    size   erasesize  name
mtd0: 00c80000 00020000 "qcadata"
mtd1: 00500000 00020000 "APPSBL"
mtd2: 00080000 00020000 "APPSBLENV"
mtd3: 00140000 00020000 "ART"
mtd4: 00200000 00020000 "kernel"
mtd5: 01800000 00020000 "rootfs"
mtd6: 00c00000 00020000 "netgear"
mtd7: 046c0000 00020000 "reserve"
mtd8: 01a00000 00020000 "firmware"
mtd9: 00010000 00001000 "m25p80"
mtd10: 0003e000 0001f000 "ART.bak"
mtd11: 0001f000 0001f000 "cert"
mtd12: 0001f000 0001f000 "config"
mtd13: 0005d000 0001f000 "pot"
mtd14: 00136000 0001f000 "language"
mtd15: 001b2000 0001f000 "traffic_meter"
mtd16: 0060e000 0001f000 "ubifs"
root@R7500:/# mtdinfo
Count of MTD devices:           17
Present MTD devices:            mtd0, mtd1, mtd2, mtd3, mtd4, mtd5, mtd6, mtd7, mtd8, mtd9, mtd10, mtd11, mtd12, mtd13, mtd14, mtd15, mtd16
Sysfs interface supported:      yes
root@R7500:/# hexdump -C /dev/mtd0ro | head
msm_nand_read_oob 0 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
00000000  d1 dc 4b 84 34 10 d7 73  5a 43 0b 7d ff ff ff ff  |..K.4..sZC.}....|
00000010  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
*
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
00000800  d1 dc 4b 84 34 10 d7 73  5a 43 0b 7d ff ff ff ff  |..Kmsm_nand_read_oob 800 800 0 failed -74, corrected 0
.4..sZC.}....|
!!! mark msm_nand offset 0x00000000 to bad block
00000810  ff ff ff ff ff ff ff ff  ff ff ff ff ff ff ff ff  |...msm_nand_read_oob 800 800 0 failed -74, corrected 0
.............|
!!! mark msm_nand offset 0x00000000 to bad block
*
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
00000840  ff ff ff ff ff ab ff ff  ff ff ff ff ff ff ff ff  |...msm_nand_read_oob 800 800 0 failed -74, corrected 0
.............|
!!! mark msm_nand offset 0x00000000 to bad block
00000850  ff ff ff ff ff ff ff ff  ff ff ff ff ff ff ff ff  |...msm_nand_read_oob 800 800 0 failed -74, corrected 0
.............|
!!! mark msm_nand offset 0x00000000 to bad block
*
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
00000a00  7a 87 08 27 ff ff ff ff  ff ff ff ff ff ff ff ff  |z..msm_nand_read_oob 800 800 0 failed -74, corrected 0
!!! mark msm_nand offset 0x00000000 to bad block
'............|

Also note that before this, I had output when connected to the serial line, but now nothing.

Any help or advice is appreciated! :wink: