Skip to content

Hardware Specifications ​

Vendor/BrandHuawei
ModelMA5671A
ODM
ChipsetLantiq PEB98035
Flash16 MB
RAM64 MB (Winbond W25Q128FV)
CPUMIPS 34Kc interAptiv
CPU Clock400MHz
SystemOpenWRT
HSGMIIYes
OpticsSC/APC
IP address192.168.1.10
Web GuiAfter root
SSH✅ user root, password admin123
Telnet
Serial✅ on SFP
Serial baud115200
Serial encoding8-N-1
Form FactorminiONT SFP
G-010S-P and MA5671A Teardown
G-010S-P and MA5671A Teardown

Firmware is interchangeable with: ​

Serial ​

The stick has a TTL 3.3v UART console (configured as 115200 8-N-1) that can be accessed from the SFP connector.

USB TTL(UART) AdapterSFP 20pins Molex connector
3.3Vpin #15 and #16
TXpin #2
RXpin #7
GNDpin #14 and #10

Note

Try PIN 10 or other GND PINs if the connection doesn't work by using PIN 14.

Note

Some USB TTL adapters label TX and RX pins the other way around: try to swap them if the connection doesn't work.

Root procedure ​

List of software versions ​

  • V8R017C00S202B

List of partitions ​

Partition layouts change depending on which image is booted, in particular:

When booting image0:

mtd2 ---> image0 (linux)
mtd5 --> image1
mtd3 --> rootfs
mtd4 --> rootfs_data

When booting image0:

mtd2 ---> image0
mtd3 --> image1 (linux)
mtd4 --> rootfs
mtd5 --> rootfs_data

For more info XPONos partition layout.

When booting from image0 ​

devsizeerasesizename
mtd00004000000010000"uboot"
mtd10008000000010000"uboot_env"
mtd20074000000010000"linux"
mtd30061eedc00010000"rootfs"
mtd40037000000010000"rootfs_data"
mtd50080000000010000"image1"

When booting from image1 ​

devsizeerasesizename
mtd00004000000010000"uboot"
mtd10008000000010000"uboot_env"
mtd20074000000010000"image0"
mtd30080000000010000"linux"
mtd4006d807700010000"rootfs"
mtd50041000000010000"rootfs_data"

List of firmwares and files ​

Info

If the root procedure without tweezers is used, the firmware already on the Huawei Stick corresponds to rooted firmware in this list.

Usage ​

Advanced settings ​

Transferring files to the stick ​

Info

If you use a modern OpenSSH version (e.g. >= 8.8) you will have to use the legacy protocol and enable some deprecated algorithms: scp -oKexAlgorithms=+diffie-hellman-group1-sha1 -oHostKeyAlgorithms=+ssh-dss [...]

sh
# scp rootfs.bin root@192.168.1.10:/tmp/

Backup of all partition ​

Make a backup of all partitions, an easy way is:

  • On the stick run:
sh
cat /proc/mtd

Via SCP ​

  • For each mtdX run in the lantiq shell:
sh
cp /dev/mtdX /tmp

Info

If you use a modern OpenSSH version (e.g. >= 8.8) you will have to use the legacy protocol and enable some deprecated algorithms: scp -oKexAlgorithms=+diffie-hellman-group1-sha1 -oHostKeyAlgorithms=+ssh-dss [...]

And in the computer shell:

sh
scp root@192.168.1.10:/tmp/mtdX ./

Via NC ​

  • For each mtdX run, on computer shell:
sh
nc -l -p 1234 > mtdX.bin

And in the lantiq shell:

sh
cat /dev/mtdX | nc 192.168.1.11 1234

Checking the currently active image ​

sh
# fw_printenv committed_image

Booting to a different image ​

sh
# fw_setenv committed_image 0|1
# fw_setenv image0|1_is_valid 1

Cloning of mtd1 (image 0) into mtd5 (image 1) ​

Warning

Image 0 can be flashed to image 1, while image 1 cannot be flashed to image 0 because it has larger rootfs_data

The following commands are used to clone image0 to image1 and then boot to it

sh
# cat /dev/mtd2 > /tmp/mtd2.bin
# mtd -e image1 write /tmp/mtd2.bin image1
# fw_setenv committed_image 1
# fw_setenv image1_is_valid 1
# reboot

Flashing a new rootfs via SSH ​

Info

Only the inactive image can be flashed

The following commands are used to flash a new rootfs to image1 and then boot to it

sh
# mtd -e image1 write /tmp/rootfs.bin image1
# fw_setenv committed_image 1
# fw_setenv image1_is_valid 1
# reboot

Warning

Some OLTs don't like when ONTs don't boot from image 0, therefore the previous procedure must be preceded by the following procedure with inverted images, as to clone image 1 into image 0

Flashing a new rootfs via serial ​

Info

We recommend using the flash web app.

If you wish to change the firmware via serial, we recommend using the web app: Web Serial Flash

Warning

Use this procedure only if you are unable to do the procedure from SSH

  1. Connecting the molex-serial adapter and the serial to the computer as indicated in Root Procedure
  2. Open Tera Term (or any other programme capable of connecting to the serial terminal)
  3. Connect the SFP stick to the SFP molex, from the terminal you will have 5 seconds to lock the bootloader by doing a simple CTRL+C. Now upload the firmware image of the new rootfs partition to the stick with the command
FALCON => loady 0x80800000

At this point it will appear:

shell requiring `mtd2` upload
shell requiring `mtd2` upload
  1. From the teratem menu do FILE → TRANSFER → YMODEM → SEND → [mtd2.bin]. It will start uploading the file at a speed of about 3-4 KBps. Now you will have to wait more than half an hour for the upload to complete.

  2. Once finished, the image loaded on the stick must also be saved to the corresponding system partition (the first of the 2) with the commands

FALCON => setenv committed_image 0
FALCON => setenv image0_is_valid 1
FALCON => saveenv
FALCON => sf probe 0 && sf erase C0000 740000 && sf write 80800000 C0000 740000 && reset

Warning

If you need to flash to image 2, you must use the following command FALCON => sf probe 0 && sf erase 800000 800000 && sf write 80800000 800000 800000 && reset

EEPROM (I2C slave simulated EEPROM) ​

The Huawei MA5671A does not have a physical EEPROM, the Falcon SOC emulates an EEPROM by exposing it on the I2C interface as required by the SFF-8472 specification.

On the I2C interface there will be two memories of 256 bytes each at the addresses 1010000X (A0h) and 1010001X (A2h), however in reality the memory available from the emulated EEPROM will be 640 bytes each but only the first 256 bytes will be exposed in the I2C interface.

The Huawei MA5671A stores the content of the emulated EEPROM in U-Boot env variables to restore it after a reboot:

  • EEPROM0 (A0h) stored in U-Boot env variable sfp_a0_low_128
  • EEPROM1 (A2h) stored in U-Boot env variable sfp_a2_info

EEPROM Editing Tool for MA5671A ​

A simple tool to help edit the EEPROM of the Huawei MA5671A, created by MrFreeZZ: https://github.com/hack-gpon/MA5671A-Eeprom/releases

✅ Automatically calculates the checksum, making the process easier and safer.

EEPROM0 layout ​

addresssizenamedefault valuedescription
BASE ID FIELDS (SFF-8472)
01Identifier0x03 (SFP)Type of transceiver
11Ext identifier0x04 (MOD_DEF 4)Additional information about the transceiver
21Connector0x01 (SC)Type of media connector
3-108Transceiver0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00Code for optical compatibility
111Encoding0x03 (NRZ)High speed serial encoding algorithm
121Signaling Rate, Nominal0x0C (1.244Gbps)Nominal signaling rate
131Rate Identifier0x00 (Not used)Type of rate select functionality
141Length (SMF,km)0x14 (20 km)Link length supported for single-mode fiber, units of km
151Length (SMF)0xC8 (200 x 100m)Link length supported for single-mode fiber, units of 100 m
161Length (50 um, OM2)0x00 (No support)Link length supported for 50 um OM2 fiber, units of 10 m
171Length (62.5 um, OM1)0x00 (No support)Link length supported for 62.5 um OM1 fiber, units of 10 m
181Length copper cable0x00 (No support)Link length supported for copper or direct attach cable, units of m
191Length (50 um, OM3)0x00 (No support)Link length supported for 50 um OM3 fiber, units of 10 m
20-3516Vendor name0x48 0x55 0x41 0x57 0x45 0x49 0x20 0x20 0x20 0x20 0x20 0x20 0x20 0x20 0x20 0x20 (HUAWEI)SFP vendor name (ASCII)
361Transceiver0x00 (No support)Code for optical compatibility
37-393Vendor OUI0x00 0x00 0x00 (No specified)SFP vendor IEEE company ID
40-5516Vendor PN0x4D 0x41 0x35 0x36 0x37 0x31 0x41 0x20 0x20 0x20 0x20 0x20 0x20 0x20 0x20 0x20 (MA5671A)Part number provided by SFP vendor (ASCII)
56-594Vendor rev0x30 0x30 0x30 0x30 (0000)Revision level for part number provided by vendor (ASCII)
60-612Wavelength0x05 0x1E (1310nm TX)Laser wavelength
621Fibre Channel Speed 20x00 (No support)Transceiver's Fibre Channel speed capabilities
631CC_BASECheck code for Base ID Fields (addresses 0 to 62)
EXTENDED ID FIELDS (SFF-8472)
64-652Options0x00 0x1A (TX DISABLE, TX FAULT, RX LOS)Indicates which optional transceiver signals are implemented
661Signaling Rate, max0x00 (No specified)Upper signaling rate margin, units of %
671Signaling Rate, min0x00 (No specified)Lower signaling rate margin, units of %
68-8316Vendor SNUnique in each SFPSerial number provided by vendor (ASCII)
84-918Date codeUnique in each SFPVendor's manufacturing date code
921Diagnostic Monitoring Type0x68 (Digital diagnostic, Internally calibrated, Received average power type)Indicates which type of diagnostic monitoring is implemented
931Enhanced Options0xE0 (Alarm/warning flags, soft TX_DISABLE control, soft TX_FAULT monitoring)Indicates which optional enhanced features are implemented
941SFF-8472 Compliance0x03 (Rev 10.2 of SFF-8472)Indicates which revision of SFF-8472 the transceiver complies with
951CC_EXTCheck code for the Extended ID Fields (addresses 64 to 94)
VENDOR SPECIFIC FIELDS
96-12732Vendor dataNot sure if it's unique or notVendor specifc data (ASCII)
128-255128Reserved0x00 0x00 0x00...Reserved
EXTRA EEPROM FIELDSNot exposed to I2C interface
256-639384Reserved0x00 0x00 0x00...Reserved

EEPROM1 layout ​

addresssizenamedefault valuedescription
DIAGNOSTIC AND CONTROL FIELDS
0-12Temp High Alarm0x5F 0x00 (95℃)Value expressed in two's complement
2-32Temp Low Alarm0xCE 0x00 (-50℃)Value expressed in two's complement
4-52Temp High Warning0x5A 0x00 (90℃)Value expressed in two's complement
6-72Temp Low Warning0xD3 0x00 (-45℃)Value expressed in two's complement
8-92Voltage High Alarm0x8C 0xA0 (3.6V)Value expressed in volt subunits[1]
10-112Voltage Low Alarm0x75 0x30 (3.0V)Value expressed in volt subunits[1:1]
12-132Voltage High Warning0x88 0xB8 (3.5V)Value expressed in volt subunits[1:2]
14-152Voltage Low Warning0x79 0x18 (3.1V)Value expressed in volt subunits[1:3]
16-172Bias High Alarm0xAF 0xC8 (90mA)Value expressed in milliampere subunits[1:4]
18-192Bias Low Alarm0x00 0x00 (0mA)Value expressed in milliampere subunits[1:5]
20-212Bias High Warning0x88 0xB8 (70mA)Value expressed in milliampere subunits[1:6]
22-232Bias Low Warning0x00 0x00 (0mA)Value expressed in milliampere subunits[1:7]
24-252TX Power High Alarm0x9B 0x82 (6dBm)Value expressed in watts subunits[1:8]
26-272TX Power Low Alarm0x22 0xD0 (-1dBm)Value expressed in watts subunits[1:9]
28-292TX Power High Warning0x7B 0x86 (5dBm)Value expressed in watts subunits[1:10]
30-312TX Power Low Warning0x2B 0xD4 (0dBm)Value expressed in watts subunits[1:11]
32-332RX Power High Alarm0x09 0xCF (-6dBm)Value expressed in watts subunits[1:12]
34-352RX Power Low Alarm0x00 0x0D (-29dBm)Value expressed in watts subunits[1:13]
36-372RX Power High Warning0x07 0xCB (-7dBm)Value expressed in watts subunits[1:14]
38-392RX Power Low Warning0x00 0x10 (-28dBm)Value expressed in watts subunits[1:15]
40-456MAC addressUnique in each SFPContains the mac address of the SFP, it could also be empty
46-5510Reserved0x00 0x00 0x00...Reserved
56-594RX_PWR(4) Calibration0x00 0x00 0x00 0x004th order RSSI calibration coefficient
60-634RX_PWR(3) Calibration0x00 0x00 0x00 0x003rd order RSSI calibration coefficient
64-674RX_PWR(2) Calibration0x00 0x00 0x00 0x002nd order RSSI calibration coefficient
68-714RX_PWR(1) Calibration0x3F 0x80 0x00 0x001st order RSSI calibration coefficient
72-754RX_PWR(0) Calibration0x00 0x00 0x00 0x000th order RSSI calibration coefficient
76-772TX_I(Slope) Calibration0x01 0x00Slope for Bias calibration
78-792TX_I(Offset) Calibration0x00 0x00Offset for Bias calibration
80-812TX_PWR(Slope) Calibration0x01 0x00Slope for TX Power calibration
82-832TX_PWR(Offset) Calibration0x00 0x00Offset for TX Power calibration
84-852T(Slope) Calibration0x01 0x00Slope for Temperature calibration
86-872T(Offset) Calibration0x00 0x00Offset for Temperature calibration, in units of 256ths °C
88-892V(Slope) Calibration0x01 0x00Slope for VCC calibration
90-912V(Offset) Calibration0x00 0x00Offset for VCC calibration
92-943Reserved0x00 0x00 0x00Reserved
951CC_DMICheck code for Base Diagnostic Fields (addresses 0 to 94)
961Temperature MSBInternally measured module temperature
971Temperature LSB
981Vcc MSBInternally measured supply voltage in transceiver
991Vcc LSB
1001TX Bias MSBInternally measured TX Bias Current
1011TX Bias LSB
1021TX Power MSBMeasured TX output power
1031TX Power LSB
1041RX Power MSBMeasured RX input power
1051RX Power LSB
106-1094Optional Diagnostics0xFF 0xFF 0xFF 0xFF (No support)Monitor Data for Optional Laser temperature and TEC current
1101Status/Control0x00 (No support)Optional Status and Control Bits
1111Reserved0x00Reserved
112-1132Alarm FlagsSupportedDiagnostic Alarm Flag Status Bits
1141Tx Input EQ control0xFF (No support)Tx Input equalization level control
1151Rx Out Emphasis control0xFF (No support)Rx Output emphasis level control
116-1172Warning FlagsSupportedDiagnostic Warning Flag Status Bits
118-1192Ext Status/Control0x00 0x00 (No support)Extended module control and status bytes
GENERAL USE FIELDS
120-1267Vendor Specific0x70 0x00 0x00 0x00 0x00 0x00 0x00Vendor specific memory addresses
1271Table Select0x00Optional Page Select
USER WRITABLE EEPROM
128-19063Reserved0xFF 0xFF 0xFF...Reserved
191-21424GPON LOID or PLOAMDepends on the configuration of the SFPGPON Logical ONU ID or PLOAM, depends on GPON LOID/PLOAM switch
215-23117GPON LPWDDepends on the configuration of the SFPGPON Logical Password
2321GPON LOID/PLOAM switchDepends on the configuration of the SFP0x01 to enable LOID, 0x02 to enable PLOAM
233-2408GPON SNUnique in each SFPGPON Serial Number (ME 256)
241-2477Reserved0xFF 0xFF 0xFF...Reserved
248-2558Vendor Control0xFF 0xFF 0xFF... (Not used)Vendor specific control functions
EXTRA EEPROM FIELDSNot exposed to I2C interface
256-511256Unknown vendor specificProbably not used in current SFPs
512-53120GPON Equipment IDGPON Equipment ID (ME 257), may not work in some firmwares
532-5354GPON Vendor IDGPON Vendor ID (ME 256 and more), may not work in some firmware
536-639104ReservedReserved

Info

For more information, see the SFF-8472 Rev 10.2 specification.

Miscellaneous Links ​



  1. The subunit are 10000 times smaller than the specified unit ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎

Copyright © 2022-2026. The documentation hereby found is distributed under the terms of the MIT License. Any external reference, link or software retains its original license and is not under the control of this website. Privacy Policy.