[Solved] AX6S RB03 model bricked after sysupgrade

So, I have bought two of these AX6s RB03 models to use as AX APs.
I have followed the Installation Guide and everything worked well for a few weeks, until the new RC6.
I didn't observed that people reported sysupgrading have bricked some devices (here and here), and that was my big mistake.
After opening the device case and attaching an USB-to-TTL, I have the following logs. Can someone guide me to unbrick this device?

Welcome to minicom 2.8

OPTIONS: I18n 
Compiled on May 26 2022, 00:00:00.
Port /dev/ttyUSB0, 22:49:12

Press CTRL-A Z for help on special keys


F0: 102B 0000
F6: 0000 0000
V0: 0000 0000 [0001]
00: 0000 0000
BP: 0000 0041 [0000]
G0: 0190 0000
T0: 0000 036F [000F]
Jump to BL

UNIVPLL_CON0 = 0xFE000000!!!
mt_pll_init: Set pll frequency for 25M crystal
[PMIC_WRAP]wrap_init pass,the return value=0.
[pmic_init] Preloader Start..................
[pmic_init] MT6380 CHIP Code, reg_val = 0, 1:E2  0:E3
[pmic_init] Done...................
Chip part number:7622B
MT7622 Version: 1.2.8, (iPA) 
SSC OFF
mt_pll_post_init: mt_get_cpu_freq = 1350000Khz
mt_pll_post_init: mt_get_mem_freq = 1600000Khz
mt_pll_post_init: mt_get_bus_freq = 279980Khz
[PLFM] Init I2C: OK(0)

[BLDR] Build Time: 20210316-161525
==== Dump RGU Reg ========
RGU MODE:     4D
RGU LENGTH:   FFE0
RGU STA:      0
RGU INTERVAL: FFF
RGU SWSYSRST: 8000
==== Dump RGU Reg End ====
RGU: g_rgu_satus:0
 mtk_wdt_mode_config  mode value=10, tmp:22000010
PL P ON
WDT does not trigger reboot
WDT NONRST=0x20000000
WDT IRQ_EN=0x340003
RGU mtk_wdt_init:MTK_WDT_DEBUG_CTL(590200F3)
[EMI] MDL number = 2
[EMI] DRAMC calibration start

[DDR] Gating glitch patched (0<cnt<=6)
[EMI] DRAMC calibration end

[EMI]rank size auto detect
[EMI]start_addr[0x40000000]=0x12345678, test_addr[0x48000000]= 0xEDCBA987
[EMI]start_addr[0x40000000]=0xEDCBA987, test_addr[0x50000000]= 0xEDCBA987
[EMI]rank0 size: 0x10000000
[MEM] complex R/W mem test pass
RAM_CONSOLE wdt status (0x0)=0x0
mtk_snand_get_device_info 
2-Recognize NAND: ID [C8 51 ], Device Name [GD5F1GQ5UEYIG], Page Size [2048]B Spare Size [128]B Total Size [128]MB
[BBT] BMT.v2 is found at 0x3FF
[PLFM] Init Boot Device: OK(0)

[PART] blksz: 2048B
[PART] [0x0000000000000000-0x000000000007FFFF] "PRELOADER" (256 blocks) 
[PART] [0x0000000000080000-0x00000000000BFFFF] "tee1" (128 blocks) 
[PART] [0x00000000000C0000-0x000000000013FFFF] "lk" (256 blocks) 

Device APC domain init setup:

Domain Setup (0x0)
Domain Setup (0x0)
Device APC domain after setup:
Domain Setup (0x0)
Domain Setup (0x0)
[PART] Image with part header
[PART] name : U-Boot
[PART] addr : 41E00000h mode : -1
[PART] size : 356560
[PART] magic: 58881688h

[PART] load "lk" from 0x00000000000C0200 (dev) to 0x41E00000 (mem) [SUCCESS]
[PART] load speed: 15827KB/s, 356560 bytes, 22ms
load lk (ret=0)
[PART] Image with part header
[PART] name : atf
[PART] addr : FFFFFFFFh mode : -1
[PART] size : 57936
[PART] magic: 58881688h

[PART] load "tee1" from 0x0000000000080200 (dev) to 0x43000DC0 (mem) [SUCCESS]
Erasing NAND...
[mtk_nand_erase_hw] mtk_nand_erase_hw @4249, ret:0x40. page:0x280 
Erasing at 0x140000 -- 100% complete.
Writing to NAND... OK
Booting System 1

NAND read: device 0 offset 0x2c0000, size 0x2000
 8192 bytes read: OK
[do_read_image_blks] This is a FIT image,img_size = 0x396b30
[do_read_image_blks] img_blks = 0x72e
[do_read_image_blks] img_align_size = 0x397000

NAND read: device 0 offset 0x2c0000, size 0x397000
 3764224 bytes read: OK
bootm flag=0, states=70f
## Loading kernel from FIT Image at 4007ff28 ...
   Using 'config-1' configuration
   Trying 'kernel-1' kernel subimage
     Description:  ARM64 OpenWrt Linux-5.10.134
     Type:         Kernel Image
     Compression:  lzma compressed
     Data Start:   0x40080014
     Data Size:    3732367 Bytes = 3.6 MiB
     Architecture: AArch64
     OS:           Linux
     Load Address: 0x44000000
     Entry Point:  0x44000000
     Hash algo:    crc32
     Hash value:   aa973e39
     Hash algo:    sha1
     Hash value:   44aa90467f8429ce5e319a9095e36ff7a93d4094
   Verifying Hash Integrity ... crc32+ sha1+ OK
## Loading fdt from FIT Image at 4007ff28 ...
   Using 'config-1' configuration
   Trying 'fdt-1' fdt subimage
     Description:  ARM64 OpenWrt xiaomi_redmi-router-ax6s device tree blob
     Type:         Flat Device Tree
     Compression:  uncompressed
     Data Start:   0x4040f4ec
     Data Size:    28699 Bytes = 28 KiB
     Architecture: AArch64
     Hash algo:    crc32
     Hash value:   5266c96c
     Hash algo:    sha1
     Hash value:   971ba76339e05a4af50e447c1c18ffe13e6b9242
   Verifying Hash Integrity ... crc32+ sha1+ OK
   Booting using the fdt blob at 0x4040f4ec
   Uncompressing Kernel Image ... OK
   Loading Device Tree to 4cf39000, end 4cf4301a ... OK

Starting kernel ...

[ATF][     7.830654]save kernel info
[ATF][     7.833591]Kernel_EL2
[ATF][     7.836261]Kernel is 64Bit
[ATF][     7.839349]pc=0x44000000, r0=0x4cf39000, r1=0x0
INFO:    BL3-1: Preparing for EL3 exit to normal world, Kernel
INFO:    BL3-1: Next image address = 0x44000000
INFO:    BL3-1: Next image spsr = 0x3c9
[ATF][     7.857047]el3_exit
[    0.000000] Booting Linux on physical CPU 0x0000000000 [0x410fd034]
[    0.000000] Linux version 5.10.134 (builder@buildhost) (aarch64-openwrt-linux-musl-gcc (OpenWrt GCC 11.2.0 r19590-042d558536) 11.2.0, GNU ld (GNU Binutils) 2.37) #0 SMP Sun Jul 31 2
[    0.000000] Machine model: Xiaomi Redmi Router AX6S
[    0.000000] Zone ranges:
[    0.000000]   DMA      [mem 0x0000000040000000-0x000000004fffffff]
[    0.000000]   DMA32    empty
[    0.000000]   Normal   empty
[    0.000000] Movable zone start for each node
[    0.000000] Early memory node ranges
[    0.000000]   node   0: [mem 0x0000000040000000-0x0000000042ffffff]
[    0.000000]   node   0: [mem 0x0000000043000000-0x000000004302ffff]
[    0.000000]   node   0: [mem 0x0000000043030000-0x000000004fffffff]
[    0.000000] Initmem setup node 0 [mem 0x0000000040000000-0x000000004fffffff]
[    0.000000] On node 0 totalpages: 65536
[    0.000000]   DMA zone: 1024 pages used for memmap
[    0.000000]   DMA zone: 0 pages reserved
[    0.000000]   DMA zone: 65536 pages, LIFO batch:15
[    0.000000] psci: probing for conduit method from DT.
[    0.000000] psci: PSCIv0.2 detected in firmware.
[    0.000000] psci: Using standard PSCI v0.2 function IDs
[    0.000000] psci: Trusted OS migration not required
[    0.000000] percpu: Embedded 20 pages/cpu s43992 r8192 d29736 u81920
[    0.000000] pcpu-alloc: s43992 r8192 d29736 u81920 alloc=20*4096
[    0.000000] pcpu-alloc: [0] 0 [0] 1 
[    0.000000] Detected VIPT I-cache on CPU0
[    0.000000] CPU features: detected: ARM erratum 845719
[    0.000000] CPU features: kernel page table isolation disabled by kernel configuration
[    0.000000] CPU features: detected: ARM erratum 843419
[    0.000000] Built 1 zonelists, mobility grouping on.  Total pages: 64512
[    0.000000] Kernel command line: console=ttyS0,115200n1 loglevel=8 swiotlb=512 rootfstype=squashfs firmware=1 uart_en=1
[    0.000000] Dentry cache hash table entries: 32768 (order: 6, 262144 bytes, linear)
[    0.000000] Inode-cache hash table entries: 16384 (order: 5, 131072 bytes, linear)
[    0.000000] mem auto-init: stack:off, heap alloc:off, heap free:off
[    0.000000] Memory: 232880K/262144K available (8254K kernel code, 894K rwdata, 1440K rodata, 448K init, 300K bss, 29264K reserved, 0K cma-reserved)
[    0.000000] SLUB: HWalign=64, Order=0-3, MinObjects=0, CPUs=2, Nodes=1
[    0.000000] rcu: Hierarchical RCU implementation.
[    0.000000]  Tracing variant of Tasks RCU enabled.
[    0.000000] rcu: RCU calculated value of scheduler-enlistment delay is 10 jiffies.
[    0.000000] NR_IRQS: 64, nr_irqs: 64, preallocated irqs: 0
[    0.000000] GIC: GICv2 detected, but range too small and irqchip.gicv2_force_probe not set
[    0.000000] arch_timer: cp15 timer(s) running at 12.50MHz (phys).
[    0.000000] clocksource: arch_sys_counter: mask: 0xffffffffffffff max_cycles: 0x2e2049cda, max_idle_ns: 440795202628 ns
[    0.000003] sched_clock: 56 bits at 12MHz, resolution 80ns, wraps every 4398046511080ns
[    0.000189] Calibrating delay loop (skipped), value calculated using timer frequency.. 25.00 BogoMIPS (lpj=125000)
[    0.000198] pid_max: default: 32768 minimum: 301
[    0.000270] Mount-cache hash table entries: 512 (order: 0, 4096 bytes, linear)
[    0.000277] Mountpoint-cache hash table entries: 512 (order: 0, 4096 bytes, linear)
[    0.001283] rcu: Hierarchical SRCU implementation.
[    0.001382] dyndbg: Ignore empty _ddebug table in a CONFIG_DYNAMIC_DEBUG_CORE build
[    0.001569] smp: Bringing up secondary CPUs ...
[    0.001902] Detected VIPT I-cache on CPU1
[    0.001945] CPU1: Booted secondary processor 0x0000000001 [0x410fd034]
[    0.002006] smp: Brought up 1 node, 2 CPUs
[    0.002013] SMP: Total of 2 processors activated.
[    0.002018] CPU features: detected: 32-bit EL0 Support
[    0.002022] CPU features: detected: CRC32 instructions
[    0.002132] CPU: All CPU(s) started at EL2
[    0.002143] alternatives: patching kernel code
[    0.005335] clocksource: jiffies: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 19112604462750000 ns
[    0.005353] futex hash table entries: 512 (order: 3, 32768 bytes, linear)
[    0.005436] pinctrl core: initialized pinctrl subsystem
[    0.006566] NET: Registered protocol family 16
[    0.006871] DMA: preallocated 128 KiB GFP_KERNEL pool for atomic allocations
[    0.006895] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA pool for atomic allocations
[    0.006919] DMA: preallocated 128 KiB GFP_KERNEL|GFP_DMA32 pool for atomic allocations
[    0.007188] thermal_sys: Registered thermal governor 'fair_share'
[    0.007191] thermal_sys: Registered thermal governor 'bang_bang'
[    0.007196] thermal_sys: Registered thermal governor 'step_wise'
[    0.007199] thermal_sys: Registered thermal governor 'user_space'
[    0.007416] ASID allocator initialised with 65536 entries
[    0.007847] pstore: Registered ramoops as persistent store backend
[    0.007853] ramoops: using 0x10000@0x42ff0000, ecc: 0
[    0.033020] cryptd: max_cpu_qlen set to 1000
[    0.034792] SCSI subsystem initialized
[    0.034919] libata version 3.00 loaded.
[    0.035080] usbcore: registered new interface driver usbfs
[    0.035107] usbcore: registered new interface driver hub
[    0.035132] usbcore: registered new device driver usb
[    0.036164] clocksource: Switched to clocksource arch_sys_counter
[    0.036711] NET: Registered protocol family 2
[    0.036811] IP idents hash table entries: 4096 (order: 3, 32768 bytes, linear)
[    0.037161] tcp_listen_portaddr_hash hash table entries: 256 (order: 0, 4096 bytes, linear)
[    0.037178] TCP established hash table entries: 2048 (order: 2, 16384 bytes, linear)
[    0.037195] TCP bind hash table entries: 2048 (order: 3, 32768 bytes, linear)
[    0.037223] TCP: Hash tables configured (established 2048 bind 2048)
[    0.037287] UDP hash table entries: 256 (order: 1, 8192 bytes, linear)
[    0.037302] UDP-Lite hash table entries: 256 (order: 1, 8192 bytes, linear)
[    0.037384] NET: Registered protocol family 1
[    0.037403] PCI: CLS 0 bytes, default 64
[    0.039888] workingset: timestamp_bits=46 max_order=16 bucket_order=0
[    0.042439] squashfs: version 4.0 (2009/01/31) Phillip Lougher
[    0.042448] jffs2: version 2.2 (NAND) (SUMMARY) (LZMA) (RTIME) (CMODE_PRIORITY) (c) 2001-2006 Red Hat, Inc.
[    0.075924] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 250)
[    0.080283] mt-pmic-pwrap 10001000.pwrap: unexpected interrupt int=0x1
[    0.094719] Serial: 8250/16550 driver, 16 ports, IRQ sharing enabled
[    0.096654] printk: console [ttyS0] disabled
[    0.116860] 11002000.serial: ttyS0 at MMIO 0x11002000 (irq = 21, base_baud = 1562500) is a ST16650V2
[    0.709713] printk: console [ttyS0] enabled
[    0.714787] mtk_rng 1020f000.rng: registered RNG driver
[    0.714963] random: crng init done
[    0.720210] cacheinfo: Unable to detect cache hierarchy for CPU 0
[    0.731788] loop: module loaded
[    0.734931] Loading iSCSI transport class v2.0-870.
[    0.740953] mtk-snand 1100d000.snfi: chip is GD5F1GQ5xExxG, size 128MB, page size 2048, oob size 128
[    0.752103] [BBT] BMT.v2 is found at 0x3ff
[    0.756456] 10 fixed-partitions partitions found on MTD device 1100d000.snfi
[    0.763494] Creating 10 MTD partitions on "1100d000.snfi":
[    0.768995] 0x000000000000-0x000000080000 : "Preloader"
[    0.775401] 0x000000080000-0x0000000c0000 : "ATF"
[    0.780790] 0x0000000c0000-0x000000140000 : "u-boot"
[    0.786834] 0x000000140000-0x000000180000 : "u-boot-env"
[    0.792791] 0x000000180000-0x0000001c0000 : "bdata"
[    0.798359] 0x0000001c0000-0x000000240000 : "factory"
[    0.804496] 0x000000240000-0x000000280000 : "crash"
[    0.810044] 0x000000280000-0x0000002c0000 : "crash_log"
[    0.815919] 0x0000002c0000-0x0000006c0000 : "kernel"
[    0.828993] no rootfs found after FIT image in "kernel"
[    0.834214] 0x0000006c0000-0x0000075c0000 : "ubi"
[    1.073757] mtk_soc_eth 1b100000.ethernet eth0: mediatek frame engine at 0xffffffc011c60000, irq 30
[    1.083306] i2c /dev entries driver
[    1.087771] mtk-wdt 10212000.watchdog: Watchdog enabled (timeout=31 sec, nowayout=0)
[    1.098455] NET: Registered protocol family 10
[    1.103618] Segment Routing with IPv6
[    1.107338] NET: Registered protocol family 17
[    1.111802] bridge: filtering via arp/ip/ip6tables is no longer available by default. Update your scripts to load br_netfilter if you need this.
[    1.124856] 8021q: 802.1Q VLAN Support v1.8
[    1.130324] pstore: Using crash dump compression: deflate
[    1.144652] mtk-pcie 1a143000.pcie: host bridge /pcie@1a143000 ranges:
[    1.151213] mtk-pcie 1a143000.pcie: Parsing ranges property...
[    1.157056] mtk-pcie 1a143000.pcie:      MEM 0x0020000000..0x0027ffffff -> 0x0020000000
[    1.191567] mtk-pcie 1a143000.pcie: PCI host bridge to bus 0000:00
[    1.197756] pci_bus 0000:00: root bus resource [bus 00-ff]
[    1.203234] pci_bus 0000:00: root bus resource [mem 0x20000000-0x27ffffff]
[    1.210104] pci_bus 0000:00: scanning bus
[    1.214148] pci 0000:00:00.0: [14c3:3258] type 01 class 0x060400
[    1.220178] pci 0000:00:00.0: reg 0x10: [mem 0x00000000-0x1ffffffff 64bit pref]
[    1.228843] pci_bus 0000:00: fixups for bus
[    1.233021] pci 0000:00:00.0: scanning [bus 00-00] behind bridge, pass 0
[    1.239718] pci 0000:00:00.0: bridge configuration invalid ([bus 00-00]), reconfiguring
[    1.247730] pci 0000:00:00.0: scanning [bus 00-00] behind bridge, pass 1
[    1.254512] pci_bus 0000:01: scanning bus
[    1.258735] pci 0000:01:00.0: [14c3:7915] type 00 class 0x000280
[    1.264911] pci 0000:01:00.0: reg 0x10: [mem 0x00000000-0x000fffff 64bit pref]
[    1.272234] pci 0000:01:00.0: reg 0x18: [mem 0x00000000-0x00003fff 64bit pref]
[    1.279558] pci 0000:01:00.0: reg 0x20: [mem 0x00000000-0x00000fff 64bit pref]
[    1.287514] pci 0000:01:00.0: supports D1 D2
[    1.291775] pci 0000:01:00.0: PME# supported from D0 D1 D2 D3hot D3cold
[    1.298408] pci 0000:01:00.0: PME# disabled
[    1.302886] pci 0000:01:00.0: 2.000 Gb/s available PCIe bandwidth, limited by 2.5 GT/s PCIe x1 link at 0000:00:00.0 (capable of 4.000 Gb/s with 5.0 GT/s PCIe x1 link)
[    1.347325] pci_bus 0000:01: fixups for bus
[    1.351502] pci_bus 0000:01: bus scan returning with max=01
[    1.357081] pci_bus 0000:01: busn_res: [bus 01-ff] end is updated to 01
[    1.363690] pci_bus 0000:00: bus scan returning with max=01
[    1.369275] pci 0000:00:00.0: BAR 0: no space for [mem size 0x200000000 64bit pref]
[    1.376927] pci 0000:00:00.0: BAR 0: failed to assign [mem size 0x200000000 64bit pref]
[    1.384922] pci 0000:00:00.0: BAR 8: assigned [mem 0x20000000-0x201fffff]
[    1.391708] pci 0000:01:00.0: BAR 0: assigned [mem 0x20000000-0x200fffff 64bit pref]
[    1.399530] pci 0000:01:00.0: BAR 2: assigned [mem 0x20100000-0x20103fff 64bit pref]
[    1.407355] pci 0000:01:00.0: BAR 4: assigned [mem 0x20104000-0x20104fff 64bit pref]
[    1.415173] pci 0000:00:00.0: PCI bridge to [bus 01]
[    1.420137] pci 0000:00:00.0:   bridge window [mem 0x20000000-0x201fffff]
[    1.426994] pcieport 0000:00:00.0: of_irq_parse_pci: failed with rc=-22
[    1.433600] pcieport 0000:00:00.0: assign IRQ: got 0
[    1.438570] pcieport 0000:00:00.0: enabling device (0000 -> 0002)
[    1.444672] pcieport 0000:00:00.0: enabling bus mastering
[    1.450490] mtk_hsdma 1b007000.dma-controller: Using 3 as missing dma-requests property
[    1.458688] mtk_hsdma 1b007000.dma-controller: MediaTek HSDMA driver registered
[    1.513465] mt7530 mdio-bus:00 wan (uninitialized): PHY [mt7530-0:01] driver [MediaTek MT7531 PHY] (irq=138)
[    1.533081] mt7530 mdio-bus:00 lan1 (uninitialized): PHY [mt7530-0:02] driver [MediaTek MT7531 PHY] (irq=139)
[    1.552711] mt7530 mdio-bus:00 lan2 (uninitialized): PHY [mt7530-0:03] driver [MediaTek MT7531 PHY] (irq=140)
[    1.572340] mt7530 mdio-bus:00 lan3 (uninitialized): PHY [mt7530-0:04] driver [MediaTek MT7531 PHY] (irq=141)
[    1.583932] mt7530 mdio-bus:00: configuring for fixed/2500base-x link mode
[    1.590977] DSA: tree 0 setup
[    1.591170] mt7530 mdio-bus:00: Link is Up - 2.5Gbps/Full - flow control rx/tx
[    1.594672] UBI: auto-attach mtd9
[    1.604480] ubi0: attaching mtd9
[    2.183995] ubi0: scanning is finished
[    2.193318] ubi0: attached mtd9 (name "ubi", size 111 MiB)
[    2.198804] ubi0: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes
[    2.205669] ubi0: min./max. I/O unit sizes: 2048/2048, sub-page size 2048
[    2.212452] ubi0: VID header offset: 2048 (aligned 2048), data offset: 4096
[    2.219407] ubi0: good PEBs: 888, bad PEBs: 0, corrupted PEBs: 0
[    2.225404] ubi0: user volume: 0, internal volumes: 1, max. volumes count: 128
[    2.232623] ubi0: max/mean erase counter: 3/2, WL threshold: 4096, image sequence number: 672112059
[    2.241662] ubi0: available PEBs: 865, total reserved PEBs: 23, PEBs reserved for bad PEB handling: 19
[    2.251584] ubi0: background thread "ubi_bgt0d" started, PID 761
[    2.257778] /dev/root: Can't open blockdev
[    2.261866] VFS: Cannot open root device "(null)" or unknown-block(0,0): error -6
[    2.269357] Please append a correct "root=" boot option; here are the available partitions:
[    2.277717] 1f00             512 mtdblock0 
[    2.277718]  (driver?)
[    2.284242] 1f04             256 mtdblock1 
[    2.284244]  (driver?)
[    2.290774] 1f08             512 mtdblock2 
[    2.290776]  (driver?)
[    2.297304] 1f0c             256 mtdblock3 
[    2.297306]  (driver?)
[    2.303829] 1f10             256 mtdblock4 
[    2.303830]  (driver?)
[    2.310358] 1f14             512 mtdblock5 
[    2.310359]  (driver?)
[    2.316887] 1f18             256 mtdblock6 
[    2.316889]  (driver?)
[    2.323412] 1f1c             256 mtdblock7 
[    2.323413]  (driver?)
[    2.329940] 1f20            4096 mtdblock8 
[    2.329942]  (driver?)
[    2.336469] 1f24          113664 mtdblock9 
[    2.336471]  (driver?)
[    2.342994] Kernel panic - not syncing: VFS: Unable to mount root fs on unknown-block(0,0)
[    2.351249] SMP: stopping secondary CPUs
[    2.355163] Kernel Offset: disabled
[    2.358642] CPU features: 0x0000002,04002004
[    2.362901] Memory Limit: none
[    2.368874] Rebooting in 1 seconds..
\C
F0: 102B 0000
F6: 0000 0000
V0: 0000 0000 [0001]
00: 0000 0000
BP: 0000 0041 [0000]
G0: 0190 0000
T0: 0000 0305 [000F]
Jump to BL

UNIVPLL_CON0 = 0xFE000000!!!
mt_pll_init: Set pll frequency for 25M crystal
RAM_CONSOLE preloader last status: 0x0 0x0 0x0 0x0 0x0 0x0 
[PMIC_WRAP]wrap_init pass,the return value=0.
[pmic_init] Preloader Start..................
[pmic_init] MT6380 CHIP Code, reg_val = 0, 1:E2  0:E3
[pmic_init] Done...................
Chip part number:7622B
MT7622 Version: 1.2.8, (iPA) 
SSC OFF
mt_pll_post_init: mt_get_cpu_freq = 1350000Khz
mt_pll_post_init: mt_get_mem_freq = 1600000Khz
mt_pll_post_init: mt_get_bus_freq = 279980Khz
[PLFM] Init I2C: OK(0)

[BLDR] Build Time: 20210316-161525
==== Dump RGU Reg ========
RGU MODE:     14
RGU LENGTH:   FFE0
RGU STA:      40000000
RGU INTERVAL: FFF
RGU SWSYSRST: 8000
==== Dump RGU Reg End ====
RGU: g_rgu_satus:2
 mtk_wdt_mode_config  mode value=10, tmp:22000010
PL RGU RST: ??
SW reset with bypass power key flag
Find bypass powerkey flag
WDT NONRST=0x20000000
WDT IRQ_EN=0x340003
RGU mtk_wdt_init:MTK_WDT_DEBUG_CTL(590200F3)
[EMI] MDL number = 2
[EMI] DRAMC calibration start

[DDR] Gating glitch patched (0<cnt<=6)
[EMI] DRAMC calibration end

[EMI]rank size auto detect
[EMI]start_addr[0x40000000]=0x12345678, test_addr[0x48000000]= 0xEDCBA987
[EMI]start_addr[0x40000000]=0xEDCBA987, test_addr[0x50000000]= 0xEDCBA987
[EMI]rank0 size: 0x10000000
[MEM] complex R/W mem test pass
RAM_CONSOLE wdt status (0x2)=0x2
mtk_snand_get_device_info 
2-Recognize NAND: ID [C8 51 ], Device Name [GD5F1GQ5UEYIG], Page Size [2048]B Spare Size [128]B Total Size [128]MB
[BBT] BMT.v2 is found at 0x3FF
[PLFM] Init Boot Device: OK(0)

[PART] blksz: 2048B
[PART] [0x0000000000000000-0x000000000007FFFF] "PRELOADER" (256 blocks) 
[PART] [0x0000000000080000-0x00000000000BFFFF] "tee1" (128 blocks) 
[PART] [0x00000000000C0000-0x000000000013FFFF] "lk" (256 blocks) 

Device APC domain init setup:

Domain Setup (0x0)
Domain Setup (0x0)
Device APC domain after setup:
Domain Setup (0x0)
Domain Setup (0x0)
[PART] Image with part header
[PART] name : U-Boot
[PART] addr : 41E00000h mode : -1
[PART] size : 356560
[PART] magic: 58881688h

[PART] load "lk" from 0x00000000000C0200 (dev) to 0x41E00000 (mem) [SUCCESS]
[PART] load speed: 16581KB/s, 356560 bytes, 21ms
load lk (ret=0)
[PART] Image with part header
[PART] name : atf
[PART] addr : FFFFFFFFh mode : -1
[PART] size : 57936
[PART] magic: 58881688h

[PART] load "tee1" from 0x0000000000080200 (dev) to 0x43000DC0 (mem) [SUCCESS]

  *** U-Boot SPI NAND ***

     1. Load firmware 0 and bootup.
     2. Load firmware 1 and bootup.
     3. Load firmware selected by Xiaoqiang and bootup.
     U-Boot console


  Press UP/DOWN to move or Press 1~3 to choose, ENTER to select
  
  [PART] load "tee1" from 0x0000000000080200 (dev) to 0x43000DC0 (mem) [SUCCESS]
MT7622> printenv
CountryCode=CN
Router_unconfigured=0
SN=36418/K1WW17182
arch=arm
autostart=yes
baudrate=115200
board=mt7622_evb
board_name=mt7622_evb
boot_auto=bootxq
boot_fw0=run boot_rd_img;bootm
boot_fw1=run boot_rd_img;bootm
boot_rd_img=nand read ${loadaddr} 0x2C0000 2000;image_blks 2048;nand read ${loadaddr} 0x2C0000 ${img_align_size}
boot_rd_img2=nand read ${loadaddr} 0x20C0000 2000;image_blks 2048;nand read ${loadaddr} 0x20C0000 ${img_align_size}
boot_wait=on
bootargs=console=ttyS0,115200n1 loglevel=8 swiotlb=512 rootfstype=squashfs firmware=1 uart_en=1
bootcmd=bootxq
bootdelay=5
bootmenu_0=1. Load firmware 0 and bootup.=run boot_fw0
bootmenu_1=2. Load firmware 1 and bootup.=run boot_fw1
bootmenu_2=3. Load firmware selected by Xiaoqiang and bootup.=run boot_auto
bootmenu_delay=30
color=100
cpu=armv7
ethact=mtk_eth
ethaddr=00:0C:E7:11:22:33
ethaddr_wan=5c:02:14:ed:8e:d1
fdt_high=0x6c000000
filesize=0
flag_boot_rootfs=1
flag_boot_success=1
flag_boot_type=2
flag_flash_permission=1
flag_last_success=1
flag_ota_reboot=0
flag_show_upgrade_info=1
flag_try_sys1_failed=0
flag_try_sys2_failed=0
img_result=bad
invaild_env=no
ipaddr=192.168.31.1
loadaddr=0x4007FF28
miot_did=529933841
miot_key=M3QzzfNbn2j1TrhD
mode=Router
model=RB03
no_wifi_dev_times=0
nv_channel_secret=JkxpeTzfBhcpUn4S/grGJlzapQKqh8kqEnF9CutkF1E=
nv_device_id=5689dc65-1316-7d7f-0ec1-9f4efd63b260
nv_sys_pwd=a671b7ae34ff1ad9bc001f572e0648ef47fe6e0a
nv_wifi_enc=psk2
nv_wifi_enc1=psk2
nv_wifi_pwd=12345678
nv_wifi_pwd1=12345678
nv_wifi_ssid=Redmi_8ED1
nv_wifi_ssid1=Redmi_8ED1
restore_defaults=0
serverip=192.168.31.100
soc=mt7622
ssh_en=1
stderr=serial
stdin=serial
stdout=serial
telnet_en=0
uart_en=1
uboot_result=bad
vendor=mediatek
wl0_radio=1
wl0_ssid=Xiaomi_5G
wl1_radio=1
wl1_ssid=Xiaomi

Environment size: 1902/65532 bytes

What I have tried until now, without success:

Is there some special image treatment need for this situation?

If you have Windows you can try the Xiaomi repair tool and a stock image for your model.

https://bigota.miwifi.com/xiaoqiang/tools/MIWIFIRepairTool.x86.zip

https://cdn.cnbj1.fds.api.mi-img.com/xiaoqiang/rom/rb03/miwifi_rb03_firmware_8fc45_1.0.37.bin

1 Like

Thanks for replying back @Gingernut!
After some more trying, I managed it to get working again.
I was trying to flash factory and sysupgrade images, without success.
When I tried tftpboot last kernel.itb snapshot image, I got OpenWrt working again, but at that time, I was getting some issues with flashing it....
So I downloaded last sysupgrade image and forced it, so, it finally got persistent.
Many thanks!

1 Like

For someone reading it in the future:
What bricked it:
sysupgrade last "sysupgrade" image without -F option
How I unbricked it:
Attach serial, tftpboot kernel.itb image, download sysupgrade image and sysupgrade it with -F option.

1 Like

This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.