Xiaomi Magenta 5G AX5400 (CB0401)

U-Boot help:

IPQ5018# help
?       - alias for 'help'
ar8xxx_dump- Dump ar8xxx registers
base    - print or set address offset
bdinfo  - print Board Info structure
bootelf - Boot from an ELF image in memory
bootm   - boot application image from memory
bootmiwifi- bootmiwifi from flash device
bootp   - boot image via network using BOOTP/TFTP protocol
bootvx  - Boot vxWorks from an ELF image
bootz   - boot Linux zImage image from memory
btnc    -  check reset button if pressed to 5s  - if so ret 1

btni    -  init gpios for button

canary  - test stack canary
chpart  - change active partition
cmp     - memory compare
coninfo - print console devices and information
cp      - memory copy
crc32   - checksum calculation
dhcp    - boot image via network using DHCP/TFTP protocol
dm      - Driver model low level access
echo    - echo args to console
editenv - edit environment variable
env     - environment handling commands
erase   - erase FLASH memory
exectzt - execute TZT

exit    - exit script
false   - do nothing, unsuccessfully
fatinfo - print information about filesystem
fatload - load binary file from a dos filesystem
fatls   - list files in a directory (default /)
fatsize - determine a file's size
fatwrite- write file into a dos filesystem
fdt     - flattened device tree utility commands
flash   - flash part_name
        flash part_name load_addr file_size

flasherase- flerase part_name

flinfo  - print FLASH memory information
fuseipq - fuse QFPROM registers from memory

go      - start application at address 'addr'
help    - print command description/usage
i2c     - I2C sub-system
imxtract- extract a part of a multi-image
ipq5018_mdio- IPQ5018 mdio utility commands
ipq_mdio- IPQ mdio utility commands
is_sec_boot_enabled- check secure boot fuse is enabled or not

itest   - return true/false on integer compare
loop    - infinite loop on address range
md      - memory display
mii     - MII utility commands
mm      - memory modify (auto-incrementing address)
mmc     - MMC sub system
mmcinfo - display MMC info
mtdparts- define flash/nand partitions
mtest   - simple RAM read/write test
mw      - memory write (fill)
nand    - NAND sub-system
nboot   - boot from NAND device
nfs     - boot image via network using NFS protocol
nm      - memory modify (constant address)
part    - disk partition related commands
pci     - list and access PCI Configuration Space
ping    - send ICMP ECHO_REQUEST to network host
printenv- print environment variables
protect - enable or disable FLASH write protection
reset   - Perform RESET of the CPU
rmemcrash-  miwifi check and save crash buff to mtd
run     - run commands in an environment variable
runmulticore- Enable and schedule secondary cores
saveenv - save environment variables to persistent storage
secboot_image_check- check image signature. usage: tftpboot 0x44000000 miwifi_*_                                                                                                                                                             full_all.bin && secboot_image_check
secure_authenticate- authenticate the signed image

setenv  - set environment variables
setexpr - set environment variable as the result of eval expression
sf      - SPI flash sub-system
showvar - print local hushshell variables
sleep   - delay execution for some time
smeminfo- print SMEM FLASH information
source  - run script from memory
test    - minimal test like /bin/sh
tftpboot- boot image via network using TFTP protocol
tftpput - TFTP put command, for uploading files to a server
true    - do nothing, successfully
tzt     - load and run tzt

uart    - UART sub-system
ubi     - ubi commands
usb     - USB sub-system
usbboot - boot from USB device
version - print monitor, compiler and linker version
xqup    -  load image and upgrade to flash

zip     - zip a memory region

NAND layout:

root@XiaoQiang:~# cat /proc/mtd
dev:    size   erasesize  name
mtd0: 00080000 00020000 "0:SBL1"
mtd1: 00080000 00020000 "0:MIBIB"
mtd2: 00040000 00020000 "0:BOOTCONFIG"
mtd3: 00040000 00020000 "0:BOOTCONFIG1"
mtd4: 00100000 00020000 "0:QSEE"
mtd5: 00100000 00020000 "0:QSEE_1"
mtd6: 00040000 00020000 "0:DEVCFG"
mtd7: 00040000 00020000 "0:DEVCFG_1"
mtd8: 00040000 00020000 "0:CDT"
mtd9: 00040000 00020000 "0:CDT_1"
mtd10: 00080000 00020000 "0:APPSBLENV"
mtd11: 00140000 00020000 "0:APPSBL"
mtd12: 00140000 00020000 "0:APPSBL_1"
mtd13: 00100000 00020000 "0:ART"
mtd14: 00080000 00020000 "0:TRAINING"
mtd15: 00080000 00020000 "bdata"
mtd16: 00080000 00020000 "crash"
mtd17: 00080000 00020000 "crash_syslog"
mtd18: 02400000 00020000 "rootfs"
mtd19: 02400000 00020000 "rootfs_1"
mtd20: 02b00000 00020000 "overlay"
mtd21: 00383000 0001f000 "kernel"
mtd22: 01550000 0001f000 "ubi_rootfs"
mtd23: 026c0000 0001f000 "data"

nvram show

root@XiaoQiang:~# nvram show
CountryCode=DE
SN=xxx
boot_wait=on
bootargs=ubi.mtd=rootfs root=mtd:ubi_rootfs rootfstype=squashfs cnss2.bdf_integrated=0x24 cnss2.bdf_pci0=0xa0 rootwait
bootcmd=bootmiwifi
bootdelay=3
bootmenu_delay=5
color=101
eth1addr=xxx
ethaddr=xxx
fdt_high=0x4A400000
fdtcontroladdr=4a9d4004
flag_boot_rootfs=0
flag_boot_success=1
flag_boot_type=2
flag_last_success=0
flag_ota_reboot=0
flag_try_sys1_failed=0
flag_try_sys2_failed=0
flash_type=11
fsbootargs=ubi.mtd=rootfs root=mtd:ubi_rootfs rootfstype=squashfs cnss2.bdf_integrated=0x24 cnss2.bdf_pci0=0xa0
ipaddr=192.168.31.1
machid=8040003
mode=Router
model=CB0401
mtdids=nand0=nand0
no_wifi_dev_times=0
rand_key=xxx
rand_nonce=xxx
restore_defaults=0
serverip=192.168.31.100
soc_hw_version=20180101
soc_version_major=1
soc_version_minor=1
ssh_en=1
stderr=serial@78AF000
stdin=serial@78AF000
stdout=serial@78AF000
subModel=AT
telnet_en=0
uart_en=1
wl0_radio=1
wl0_ssid=Magenta_cb0401_xxx
wl1_radio=1
wl1_ssid=Magenta_cb0401_xxx

Active partition

root@XiaoQiang:~# nvram get flag_boot_rootfs
0

( mtd18: 02400000 00020000 "rootfs" )

DTS decompiled from DTB with some errors, and too big to post here.

What would be next step?
Xiaomi AX6000 got very similar hardware:
Both IPQ5018, same switch QCA8337, same 5GHz radio QCN9024.
cb0401 - 1GB RAM, ax6000 - 512MB
Both have 128MB NAND, but layout is different after mtd 19 rootfs_1

I found flashing instructions for AX6000 which I believe will be similar if not the same for cb0401

Also made full backup of NAND and have programmer, so no problem if I need to restore it.

Is there any recommended flux for resoldering?

Hi everyone!

I’m looking for help fromwho’s worked with this router (CB0401/Cb0401V2) or has experience with Xiaomi’s U-Boot. My router ended up in a hard bootloop. If I power it on while holding the reset button for about 10 - 15 sec, it goes into what looks like emergency recovery mode and just keeps blinking the orange led indicator. There’s no web interface, no wifi, nothing.

I have the official firmware: miwifi_cb0401v2_R03A05-FOTA_firmware_d61ca_3.0.85_INT_ispver-3.0.8.bin, and also have several other official firmware versions and I’ve tried flashing different ones, but they all behave exactly the same.

At this point I’ve tried three completely different recovery setups, and every single one failed in a different way. I’ll describe everything in order so I don’t have to repeat myself later.

Round 1: Xiaomi MiWiFiRepairTool + Windows virtual machines on macOS (Parallels and UTM)

I don’t have a physical Windows pc, so I used virtual machines on my Mac together with an external USB-C - ethernet adapter.

First I tried Parallels Desktop. I immediately ran into a weird issue where Parallels exposes the local C: drive through a UNC network path (something like \Mac\Home). Because of that, the xiaomi official recovery tool couldn’t even see the C: drive when clicking the Browse button. I had to work around it by typing the path manually.

Then I switched to UTM. To get rid of any virtual networking, I disabled the virtual NIC completely and passed the USB ethernet adapter directly into the Windows vm using USB passthrough. I configured a static IP (192.168.31.100 / 255.255.255.0) and completely disabled firewall and defender.

This actually got much further.

The recovery tool clearly shows the DHCP exchange. It offers the router an IP address (192.168.31.101/102 depending on the attempt), the router accepts it, requests the firmware by its full filename, and the transfer starts.

The problem is that it always dies in the middle with:

TIMEOUT waiting for Ack block #204801

The exact block number changes sometimes, but the timeout itself is always there. The router stops acknowledging packets, drops the Ethernet link, goes back into recovery mode, requests DHCP again, and repeats the whole process.

I also tried renaming the firmware to something short, but that made absolutely no difference.

Round 2: Native macOS (dnsmasq + tcpdump), no virtualization

I followed this guide: https://gist.github.com/danpawlik/ea35dc64b2d9eadc45c9e645845aaa78

I wanted to eliminate virtualization completely and serve the firmware directly from macOS.

I configured my ethernet adapter (en24) with a static IP of 192.168.31.100/24, disabled the macOS firewall completely using socketfilterfw, set up dnsmasq for both DHCP and TFTP, placed the firmware into /tmp/debrick and verified the permissions (chmod 644).

According to the router’s own logs, it expected a firmware file with a specific filename, so I renamed it to the hexadecimal format: C0A81F6B.img

Then I started packet capture: sudo tcpdump -i en24 -nn port 69

Here’s what happens every single time. The router sends DHCPDISCOVER.

dnsmasq successfully assigns it an IP address (192.168.31.107), provides the boot filename (C0A81F6B.img) and the next-server address (192.168.31.100). The router accepts all of that.

Right after that, tcpdump clearly captures the router sending a TFTP RRQ request:

192.168.31.107 > 192.168.31.100.69: RRQ “C0A81F6B.img”

And here’s the weird part. The transfer never even starts. There’s no DATA block 1. There’s no TFTP ERROR. dnsmasq stays completely silent as if it never received the RRQ, even though tcpdump clearly shows the packet arriving on the interface.

The router just keeps doing the same thing over and over:

RRQ → timeout → RRQ → timeout.

So this is where I’m at now. The bootloader is probably alive. The Ethernet controller is working. DHCP works correctly on both Windows and macOS. The router gets an IP address and clearly sees the server. The router definitely wants to download firmware because it keeps sending RRQ requests.

On Windows, the transfer starts but eventually dies with ACK timeouts.

On macOS, the transfer never even begins even though the RRQ packets definitely reach the interface.

So I have a few questions about the CB0401V2 recovery mode.

On my side TFTP behaves weird: on Windows the firmware upload starts but always fails mid-transfer, and on macOS with dnsmasq the router keeps sending RRQ requests but the actual transfer never begins.

I can’t figure out what TFTP/block size behavior this bootloader expects, because the failures are consistent but look kind of random.

I tried multiple official Xiaomi FOTA .bin files and the result is always the same, so I’m starting to think the file itself isn’t the issue.

From what I’ve seen on forums, it looks like the router might actually expect a real service/factory .img in recovery mode, not just a renamed .bin , but I’m not sure if that’s real or just speculation. Someone also mentioned that such an image exists for this model on Chinese forums, but I have no idea where to find it or if it’s still available.

So the main question is: is it even worth looking for a real “recovery .IMG”, or should the bootloader normally accept standard FOTA .bin anyway?

Also not sure if trying a clean Windows setup with MiWiFiRepairTool makes sense (to rule out USB-Ethernet timing issues), or if this is just normal Xiaomi U-Boot behavior on this device. And I can’t find any official Xiaomi docs or confirmation that MiWiFiRepairTool actually supports CB0401V2, which is confusing.

If anyone has dealt with this model or has any hints, I’d really appreciate it.

  1. This device is well known to have HW trouble. Bad soldering of motherboard components ending up in a bootloop.
  2. where did you get MiWiFiRepairTool from?

from official website miwifi:

direct link:
https://bigota.miwifi.com/xiaoqiang/tools/MIWIFIRepairTool.x86.zip

OK.

Actually I saw it before, but just did not know how it works. My china is a bit rusty.

Can anyone with a working unit test this MiWiFi Repair Tool? I'm trying to figure out if it actually works for our model (CB0401/CB0401V2) or if I'm just wasting time and need a different laptop.

I already tried a new Type-C to LAN adapter, but it crashes at the same byte count every single time. Here’s how it's supposed to work on other models:

https://www.youtube.com/watch?v=WvVIT3gXZak.

If you have one, could you check if it works for you? Any info would be great.

After four very long days I managed to build OpenWrt (almost) for this device. As a template I used Xiaomi AX6000, which is very similar.
Tested in initramfs mode only so far, but:

  • Its booting
  • Lan/Wan working
  • Both radios, including calibration and board-2.bin files ( at this point they are hardcoded )
  • Modem (which was my biggest concern) also :crossed_fingers:

Should be close to full functionality :grinning_face:

TODO:

  • FLASHING + flashing instructions
  • TESTING!
  • MACs
  • Upload board-2.bin so they are downloaded automatically by ipq-wifi
  • Leds
  • Power Button
  • ??
  • Add PR
  • Add devicepage?

Full OpenWrt bootlog :

Initramfs .itb image

Sneak peaks:

We’re very close to merging a big PR with a revised network stack, eliminating the need for qca-ssdk and qca-nss-dp entirely.

I would recommend you to apply this patch to your tree and adjust your dts accordingly.
See the ipq5018 boards for examples.

Let me know if you need any help.

PS: I’ve looked at your boot log. Is anything connected to pcie1? Because the phy doesn’t come up.

Thanks for letting me know, I will happily move to new ethernet.. once I solve secure boot problem :slightly_smiling_face:
(there is modem on pcie1)

'Let me know if you need any help.'
I do

Secureboot seem to work differently than on AX6000 or AX9000 (something I should check before porting!)

secure boot fuse is enabled
[secboot]: Secure boot is enabled!

I can boot uImage.itd via bootm 0x44000000, or boot from rootfs_1 partition:

IPQ5018# setenv mtdparts mtdparts=nand0:0xa80000(reserved),0x2400000(rootfs),0x2400000(rootfs_1),0x2b00000(overlay)
IPQ5018# ubi part rootfs_1
IPQ5018# ubi read 0x44000000 kernel
IPQ5018# bootm 0x44000000

But, when flashing initramfs through xmir-patcher, or manually as in instructions for AX9000 ( https://openwrt.org/toh/xiaomi/ax9000 )

I get

Kernel image authentication failed
BUG: failure at board/qca/arm/common/cmd_bootmiwifi.c:570/miwifi_check_flash_signedimg()!

full version:

// on OEM firmware
root@XiaoQiang:/tmp/tmp# nvram get flag_boot_rootfs
0
root@XiaoQiang:/tmp/tmp# cat /proc/mtd
dev:    size   erasesize  name
mtd0: 00080000 00020000 "0:SBL1"
mtd1: 00080000 00020000 "0:MIBIB"
mtd2: 00040000 00020000 "0:BOOTCONFIG"
mtd3: 00040000 00020000 "0:BOOTCONFIG1"
mtd4: 00100000 00020000 "0:QSEE"
mtd5: 00100000 00020000 "0:QSEE_1"
mtd6: 00040000 00020000 "0:DEVCFG"
mtd7: 00040000 00020000 "0:DEVCFG_1"
mtd8: 00040000 00020000 "0:CDT"
mtd9: 00040000 00020000 "0:CDT_1"
mtd10: 00080000 00020000 "0:APPSBLENV"
mtd11: 00140000 00020000 "0:APPSBL"
mtd12: 00140000 00020000 "0:APPSBL_1"
mtd13: 00100000 00020000 "0:ART"
mtd14: 00080000 00020000 "0:TRAINING"
mtd15: 00080000 00020000 "bdata"
mtd16: 00080000 00020000 "crash"
mtd17: 00080000 00020000 "crash_syslog"
mtd18: 02400000 00020000 "rootfs"
mtd19: 02400000 00020000 "rootfs_1"
mtd20: 02b00000 00020000 "overlay"
mtd21: 00383000 0001f000 "kernel"
mtd22: 01550000 0001f000 "ubi_rootfs"
mtd23: 026c0000 0001f000 "data"
root@XiaoQiang:/tmp/tmp# ubiformat /dev/mtd19 -y -f openwrt-qualcommax-ipq50xx-x
iaomi_cb0401-initramfs-factory.ubi
ubiformat: mtd19 (nand), size 37748736 bytes (36.0 MiB), 288 eraseblocks of 131072 bytes (128.0 KiB), min. I/O size 2048 bytes
libscan: scanning eraseblock 287 -- 100 % complete
ubiformat: 288 eraseblocks have valid erase counter, mean value is 5
ubiformat: flashing eraseblock 176 -- 100 % complete
ubiformat: formatting eraseblock 287 -- 100 % complete
root@XiaoQiang:/tmp/tmp# nvram set flag_boot_rootfs=1
root@XiaoQiang:/tmp/tmp# nvram set flag_last_success=1
root@XiaoQiang:/tmp/tmp# nvram commit

// After powering down, then up

Format: Log Type - Time(microsec) - Message - Optional Info
Log Type: B - Since Boot(Power On Reset),  D - Delta,  S - Statistic
S - QC_IMAGE_VERSION_STRING=BOOT.BF.3.3.1.1-00067
S - IMAGE_VARIANT_STRING=MAACANAZA
S - OEM_IMAGE_VERSION_STRING=CRM
S - Boot Config, 0x000002c5
B -       127 - PBL, Start
B -      1560 - bootable_media_detect_entry, Start
B -      3355 - bootable_media_detect_success, Start
B -      3358 - elf_loader_entry, Start
B -      8369 - auth_hash_seg_entry, Start
B -     29343 - auth_hash_seg_exit, Start
B -    120874 - elf_segs_hash_verify_entry, Start
B -    190484 - PBL, End
B -    155946 - SBL1, Start
B -    217312 - GCC [RstStat:0x0, RstDbg:0x600000] WDog Stat : 0x4
B -    225486 - clock_init, Start
D -      7198 - clock_init, Delta
B -    232837 - boot_flash_init, Start
D -     14945 - boot_flash_init, Delta
B -    247843 - boot_config_data_table_init, Start
D -      4666 - boot_config_data_table_init, Delta - (575 Bytes)
B -    255590 - Boot Setting :  0x00000618
B -    261964 - CDT version:2,Platform ID:8,Major ID:4,Minor ID:0,Subtype:3
B -    268705 - sbl1_ddr_set_params, Start
B -    270108 - Pre_DDR_clock_init, Start
B -    275964 - Pre_DDR_clock_init, End
B -    917836 - do ddr sanity test, Start
D -        30 - do ddr sanity test, Delta
B -    922503 - Image Load, Start
D -    253119 - QSEE Image Loaded, Delta - (586580 Bytes)
B -   1176476 - Image Load, Start
D -     23943 - DEVCFG Image Loaded, Delta - (19992 Bytes)
B -   1200480 - Image Load, Start
D -    191296 - APPSBL Image Loaded, Delta - (440117 Bytes)
B -   1391867 - QSEE Execution, Start
D -        30 - QSEE Execution, Delta
B -   1398333 - SBL1, End
D -   1245041 - SBL1, Delta
S - Flash Throughput, 2458 KB/s  (1047936 Bytes,  426232 us)
S - DDR Frequency, 800 MHz
S - Core 0 Frequency, 800 MHz
bootwait is on, bootdelay=3
### main_loop: bootcmd="bootmiwifi"
Hit any key to stop autoboot:  0
  miwifi: check crash in rmem !
 trigger button release!
secure boot fuse is enabled
[secboot]: Secure boot is enabled!
do_bootmiwifi: do_boot_signedimg
miwifi_get_os_index: flag_try_sys1_failed=0
miwifi_get_os_index: flag_try_sys2_failed=0
miwifi_get_os_index: flag_ota_reboot=0
miwifi_get_os_index: flag_last_success=1
miwifi_get_os_index: flag_boot_rootfs=1
miwifi_get_os_index: try_sys_failed=0, flag_boot_rootfs=1
miwifi_config_env: ox_idx = 1, ft_mode = 0
miwifi_config_env: flag_try_sys2_failed=1
miwifi_config_env: flag_ota_reboot=0
Erasing NAND...
Erasing at 0x4e0000 -- 100% complete.
Writing to NAND... OK
miwifi_bootargs: ubi.mtd=rootfs_1 root=mtd:ubi_rootfs rootfstype=squashfs cnss2.bdf_integrated=0x24 cnss2.bdf_pci0=0xa0 rootwait uart_en=1
ubi0: attaching mtd1
ubi0: scanning is finished
ubi0: attached mtd1 (name "mtd=0", size 36 MiB)
ubi0: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes
ubi0: min./max. I/O unit sizes: 2048/2048, sub-page size 2048
ubi0: VID header offset: 2048 (aligned 2048), data offset: 4096
ubi0: good PEBs: 288, bad PEBs: 0, corrupted PEBs: 0
ubi0: user volume: 1, internal volumes: 1, max. volumes count: 128
ubi0: max/mean erase counter: 6/6, WL threshold: 4096, image sequence number: 413436238
ubi0: available PEBs: 89, total reserved PEBs: 199, PEBs reserved for bad PEB handling: 20
Read 0 bytes from volume kernel to 44000000
No size specified -> Using max size (22220800)
Kernel image authentication failed
BUG: failure at board/qca/arm/common/cmd_bootmiwifi.c:570/miwifi_check_flash_signedimg()!
BUG!
resetting ...

Format: Log Type - Time(microsec) - Message - Optional Info
Log Type: B - Since Boot(Power On Reset),  D - Delta,  S - Statistic
S - QC_IMAGE_VERSION_STRING=BOOT.BF.3.3.1.1-00067
S - IMAGE_VARIANT_STRING=MAACANAZA
S - OEM_IMAGE_VERSION_STRING=CRM
S - Boot Config, 0x000002c5
B -       127 - PBL, Start

tries to boot 3 times, then it goes back to OEM firmware
Changing bootcmd +saveenv persist after reset, but is ignored and bootmiwifi is fired instead.

Will try to downgrade from 3.0.16 to 3.0.10, but have low hopes it will change anything

If you’re able to change bootcmd in uboot, check step 5 in the flash instructions of the Linksys mx6200 which also has secure boot enabled. We were able to bypass it:

It works diffrently for xiaomi than linksys

I am able to change bootcmd, but its being ignored with autoboot path. Autoboot seem to have different path and own env, completely ignoring bootcmd or bootargs

bootwait is on, bootdelay=3
### main_loop: bootcmd="bootmiwifi"

there is do_boot_unsignedimg path, but there is check before if securboot is on

[secboot]: Secure boot is enabled!
do_bootmiwifi: do_boot_signedimg
miwifi_bootargs: ubi.mtd=rootfs_1 root=mtd:ubi_rootfs rootfstype=squashfs cnss2.bdf_integrated=0x24 cnss2.bdf_pci0=0xa0 rootwait uart_en=1

Spent a lot of time on it, and its a dead end for me.

@lytr, any ideas?

So using bootm you can only boot OEM firmware?
What does help return in u-boot?

If I stop autoboot and use u-boot prompt

IPQ5018# ubi part rootfs_1
IPQ5018# ubi read 0x44000000 kernel
IPQ5018# bootm 0x44000000

then it will boot openwrt no problem.
But if I let autoboot run, it will just ignore bootcmd - values are saved, persist reset, just wont fire,
and it goes bootmiwifi path.

IPQ5018# setenv bootcmd 'setenv mtdparts mtdparts=nand0:0xa80000(reserved),0x2400000(rootfs),0x2400000(rootfs_1),0x2b00000(overlay); ubi part rootfs_1; ubi read 0x44000000 kernel; bootm 0x44000000'
IPQ5018# saveenv

Echo also not displayed

setenv bootcmd 'echo a b c; run bootcmd2'
IPQ5018# help
?       - alias for 'help'
ar8xxx_dump- Dump ar8xxx registers
base    - print or set address offset
bdinfo  - print Board Info structure
bootelf - Boot from an ELF image in memory
bootm   - boot application image from memory
bootmiwifi- bootmiwifi from flash device
bootp   - boot image via network using BOOTP/TFTP protocol
bootvx  - Boot vxWorks from an ELF image
bootz   - boot Linux zImage image from memory
btnc    -  check reset button if pressed to 5s  - if so ret 1

btni    -  init gpios for button

canary  - test stack canary
chpart  - change active partition
cmp     - memory compare
coninfo - print console devices and information
cp      - memory copy
crc32   - checksum calculation
dhcp    - boot image via network using DHCP/TFTP protocol
dm      - Driver model low level access
echo    - echo args to console
editenv - edit environment variable
env     - environment handling commands
erase   - erase FLASH memory
exectzt - execute TZT

exit    - exit script
false   - do nothing, unsuccessfully
fatinfo - print information about filesystem
fatload - load binary file from a dos filesystem
fatls   - list files in a directory (default /)
fatsize - determine a file's size
fatwrite- write file into a dos filesystem
fdt     - flattened device tree utility commands
flash   - flash part_name
        flash part_name load_addr file_size

flasherase- flerase part_name

flinfo  - print FLASH memory information
fuseipq - fuse QFPROM registers from memory

go      - start application at address 'addr'
help    - print command description/usage
i2c     - I2C sub-system
imxtract- extract a part of a multi-image
ipq5018_mdio- IPQ5018 mdio utility commands
ipq_mdio- IPQ mdio utility commands
is_sec_boot_enabled- check secure boot fuse is enabled or not

itest   - return true/false on integer compare
loop    - infinite loop on address range
md      - memory display
mii     - MII utility commands
mm      - memory modify (auto-incrementing address)
mmc     - MMC sub system
mmcinfo - display MMC info
mtdparts- define flash/nand partitions
mtest   - simple RAM read/write test
mw      - memory write (fill)
nand    - NAND sub-system
nboot   - boot from NAND device
nfs     - boot image via network using NFS protocol
nm      - memory modify (constant address)
part    - disk partition related commands
pci     - list and access PCI Configuration Space
ping    - send ICMP ECHO_REQUEST to network host
printenv- print environment variables
protect - enable or disable FLASH write protection
reset   - Perform RESET of the CPU
rmemcrash-  miwifi check and save crash buff to mtd
run     - run commands in an environment variable
runmulticore- Enable and schedule secondary cores
saveenv - save environment variables to persistent storage
secboot_image_check- check image signature. usage: tftpboot 0x44000000 miwifi_*_full_all.bin && secboot_image_check
secure_authenticate- authenticate the signed image

setenv  - set environment variables
setexpr - set environment variable as the result of eval expression
sf      - SPI flash sub-system
showvar - print local hushshell variables
sleep   - delay execution for some time
smeminfo- print SMEM FLASH information
source  - run script from memory
test    - minimal test like /bin/sh
tftpboot- boot image via network using TFTP protocol
tftpput - TFTP put command, for uploading files to a server
true    - do nothing, successfully
tzt     - load and run tzt

uart    - UART sub-system
ubi     - ubi commands
usb     - USB sub-system
usbboot - boot from USB device
version - print monitor, compiler and linker version
xqup    -  load image and upgrade to flash

zip     - zip a memory region

Have you tried changing bootcmd in nvram?

Yes, same result, values in quote are stock