Flash on Zyxel NR7101

@bmork: So, this finally worked and I saw the update info lines coming back via picocom until 100% complete.

picocom /dev/ttyUSB2

# Set APN
# LuCi: Stop wwan0 interface
# Start upgrade

But I can't connect to the internet anymore. The wan_4 interface is now missing. Before the update, it took about 60 seconds for the wan_4 device to spawn in LUCI, it's now 10 minutes of waiting and it does not come up. Can you help me here, please?

This is my log:

Thu Mar 17 10:30:19 2022 daemon.notice netifd: wan (2129): Waiting for SIM initialization
Thu Mar 17 10:31:19 2022 daemon.notice netifd: wan (2129): PIN verification is disabled
Thu Mar 17 10:31:19 2022 daemon.notice netifd: wan (2129): Device does not support 802.3 mode. Informing driver of raw-ip only for wwan0 ..
Thu Mar 17 10:31:19 2022 daemon.notice netifd: wan (2129): Waiting for network registration
Thu Mar 17 10:31:21 2022 daemon.notice netifd: wan (2129): Device stopped network registration. Restart network registration
Thu Mar 17 10:31:22 2022 daemon.notice netifd: wan (2129): Device stopped network registration. Restart network registration
Thu Mar 17 10:31:23 2022 daemon.notice netifd: wan (2129): Device stopped network registration. Restart network registration
Thu Mar 17 10:31:24 2022 daemon.notice netifd: wan (2129): Device stopped network registration. Restart network registration

Solution: Type the following in PICOCOM:


I don't know what it is, but after that, the internet connection came back. Rebooted the device, and it automatically came up fine like before the update.

Related: https://www.lteforum.at/mobilfunk/zyxel-nr7101-fb-7530-stoerung.17104/seite-12.html

  • It's about modem upgrades and sources for the DFOTA upgrade files.

would you recomend the openwrt version for the zyxel for a daily use? Some of you used it with 5G NSA Connecting during some Days without trouble?

Mine is fine for daily use after I flashed Openwrt months ago.

To sum up:

  • zyxel firmware unexpectedly lost mobile data connection without indication on the gui (ip addr and connected was still shown but no internet access) , the network "watcher" feature did not auto heal this, I had to detect and reboot myself manually each time.
    Disadvantage: wifi cannot be used to surf the internet

  • Openwrt firmware:

Advantage: wifi can be used to surf the internet

I recommend a daily reboot as german Telekom seems to "block by routing table" that incoming ports work after approx. 24 hours of nonstop connection to the mobile network

Very rarely I had hiccups in the mobile connection, just like with the zyxel firmware. To get a self heal for this condition, I installed watchcat (opkg install....) and configured it to check the internet availability by ping every 60 secs and if 4 checks fail in a row , a reboot is triggered (modem interface restart would also suffice).

Since then, I had stable connection via 5g-nsa all time.

Last but not least, I figured out when the modem was upgraded with a DFOTA package, it has lost some settings that don't live in the openwrt world - e.g. the mode_pref setting. This should then be set to AUTO in picocom (modem serial interface terminal). Else the modem falls back to WCDMA/LTE speed which lower than the available 5G-NSA speed.

Here's the command :

picocom /dev/ttyUSB2
1 Like

It is a bit more complicated than what you say.
Problem in openwrt, is the missing of QMI, as of now, you cant use it properly in qmi on openwrt, so you have to rely on MBIM mode, which is nice, but doesn't work like qmi on this modem.
Reason being usb bus saturation, because of lack of multiplexing.
Actually you cant use qmi or ecm wiht zyxel.
Zyxel have made a lot of progress, and since zyxel have a really weak cpu, you can't really set anything strange, without compromising speed.
About dfota, you don't have to rely on Dfota package, you can just update the modem whit qfirehose, which is the real normal way to upgrade, and you can install the latest firmware, which fix lots of things.
Funny fact is, you can't use qfirehose in zyxel firmware.
Best way to use zyxel, is getting temp ROOter which have already compiled Qfirehose inside,installing latest module firmware, and get back to zyxel firmware.
Works like a breeze, with really minor tweaks.
Also V6 beta works like a charm, and they are making really nice progress, i can state without a doubt, when Stable V6 come out, openwrt won't have much sense to me.
Apart this, anyone can use what they like, but i can just advice, to stop using DFota, for your safety, because it is not the right way to do it.

Doesn't "option proto 'qmi'" in the network config tell Openwrt to use QMI mode? My speeds are (felt) quite high between 100...200 Mbit/s outside of the town area.

you can set qmi, but it will crash usb bus.
Also, why use normal wrt, while you can use ROOter and have an easy life?
anyway no, in qmi it will crash, i can reach 200 in downlload, and it crash. maybe if you stay around 100 mbps it can keep on, but after that it always crashed to me.
Need to stick whit MBIM

hey thanks for your detail replays. I found some different Models. Are there importen Hardware differences i should now?
could not found some issues and rison why i should buy the expensive r one?


Not sure about this, but I believe the EUZNN1F variant is the "Nebula NR7101". See https://www.zyxel.com/products_services/Nebula-5G-NR-Outdoor-Router-Nebula-NR7101/

If you don't know what that is, then you probably don't want it...

Hmm no problems so far here in qmi mode. I also use daily reboot during the night, as the internet connection sometimes "hangs" unusable after 24...72 hours of nonstop use.

what you use, modemmanager?

Hi all,

I also went the route of getting a used Telenor branded nr7101. I have gotten the supervisor password and a serial console, removed the iptables rules to enable access to the webinterface. However Im having issues logging into the web interface. Neither admin/supervisor/root work with the supervisor password or the default "1234".

Peeking into /data/zcfg_config.json seems to show that the supervisor and admin account is disabled - and no password set for the root account.

Any idea on how to get access to the web interface? Can i update the /data/zcfg_config.json to enable the admin account and set a password?

Will the passwords be reset to a known default if I manually flash the stock fw, either by adding it to the /root/fw directory or performing the procedure in the wiki?

> "Account":[
>           {
>             "AutoShowQuickStart":false,
>             "Enabled":true,
>             "EnableQuickStart":false,
>             "Page":"",
>             "Username":"root",
>             "Password":"",
>             "PasswordHash":"", 
>             "Privilege":"login",      
>             "AccountIdleTime":900                                 
>           },                 
>           {
>             "AutoShowQuickStart":false,
>             "Enabled":false,
>             "EnableQuickStart":false,
>             "Page":"",
>             "Username":"supervisor",
>             "Password":"",
>             "PasswordHash":"",
>             "Privilege":"login,httpd,samba",
>             "AccountIdleTime":900
>           }
> {
>             "AutoShowQuickStart":true,
>             "Enabled":false,
>             "EnableQuickStart":true,
>             "Page":"Broadband,Wireless,Home_Networking,Routing,NAT,DNS,IGMP_MLD,Vlan_Group,Interface_Grouping,Firewall,MAC_Filter,Certificates,Log,Traffic_Status,ARP_Table,Routing_Table,CellWan_Status,System,User_Account,Remote_MGM
>             "Username":"admin",
>             "Password":"",
>             "PasswordHash":"",
>             "Privilege":"login,httpd,samba"
>           }
>         ],

I booted the stock firmware from RAM using the TFTP procedure in the wiki. That allowed me to login using supervisor and the generated password (same as for SSH). I then added a new administrator account to the web interface, flashed the stock firmware from the web interface. This has left me with full access to the device. If you want to add a user to the web interface directly in the zcfg_config.json this is a working format for NEWUSERNAME/Abcde123


today i got my second NR7101 because the first one was direct "dead on arrival"
They deliefert me the second NR7101 with the Firmware V1.00(ABVC.3)C0

and Modul Version:

I'm just curious how it is with you

1 Like

Mine arrived the same way (EU version). I advise you to update the stock modem and firmware from zyxel before you put the device to daily production usage. If it still doesn't keep stable, maybe tryout openwrt a little later...
The official zyxel updates deliver 5G-NSA support which wasn't part of the old initially delivered firmware.

Hello guys.
Sorry for asking newbie questions here, but what's the easiest way of getting either Openwrt or OEM firmware into a Telenor branded NR7101?
I see there are different methods of doing this in the wiki, but I don't really understrand the "Halt boot by pressing Escape on console". I'm familiar with SSH and basics, but the tutorial in the wiki is a little bit over my head :stuck_out_tongue:

Hi and welcome.

These are the high level steps I used to get back to stock FW:

  1. Get a USB Serial adapter and connect to the on-board connector.
  2. Connect with a terminal application as the device boots up. This will give you a shell session on the device, but without using the network.
  3. Temporarily enable http/https/ssh connectivity (iptables). This will open the device to allow you to connect to it through its internal Wifi AP.
  4. Use Web GUI to flash stock Zyxel FW.
  5. Flash OpenWRT from the Zyxel web GUI (optional).

@bmork provided at lot more detail on the individual steps. the nvram command is used to set the DebugFlag and CheckBypass NVRAM variables that allows you to keep access to the bootloader.

All in all it was worth all the work. The device is very stable and fast, with good reception. I have run it without issue for 90+ days without a reboot. I was happy with stock FW so I never tried OpenWRT.

Good luck!

1 Like

Finally managed to get http and ssh running. What I did wrong was that I logged into shell with the supervisor account and not the root account. No iptables for supervisor I guess..

Now I'm wondering what to do next, I want to flash the zyxel stock fw:
Could I flash zyxel fw using the "From OEM ssh" method? Or do I need to flash Openwrt first and go to stock fw from there?

Edit: I flashed Openwrt using SSH and then flashed StockFW with OpenWrt. Then again flashed StockFW with StockFW just to make sure everything was ok. Now everything is working the way it should :slight_smile: No dropouts for one hour now so I think everything is good. Anything else I should do or must check before I close up the device again and mount it 6m up in the air? :smiley:

If you are on stable stock firmware, everything is ok. you can close and that's it.
The only thing you have to do, if you did not untill now, is putting firmware on kernel 2, because if something happen, it would pull kernel 2 firmware, which if it's telenoir locked firmware, you would get back to the start.
so whit scp upload the stable firmware, which is V5 as of now, on /tmp folder, then log ssh as root:

nvram setro uboot DebugFlag 0x1
nvram setro uboot CheckBypass 0
nvram commit
cd /tmp
mtd_write -w write 100ABUV5C0.bin Kernel2

Then you are done for good.

Log in as “supervisor” on

the default IP of my NR7101 is
when I try to connect to it does not work ( PC IP manually set to )
when I try to login to admin & pw from label works
but supervisor with password from generator (correct IMEI) does not work.
(nor does SSH with root )
does this work only with older firmware ?

Not IMEI. Serialnumber of the router. This looks like Syy0Zwwnnnnnn