Reverse engineering BMS Firmware / Reflashing BMS

My Nissan Leaf Forum

Help Support My Nissan Leaf Forum:

This site may earn a commission from merchant affiliate links, including eBay, Amazon, and others.
Hi! Amazing project!! I hear that Kangoo/Fluence ZE BMS have unlocked V850. Can protocol is different in Renault and Nissan. But maybe full flash with bootloader from Kangoo BMS can help for reverse engineering)

In Ukraine my friend start change chip in Leaf BMS for custom, long time ago (maybe 6 year ago), and now he have more than 300 OEM chip))
 
Hi! Amazing project!! I hear that Kangoo/Fluence ZE BMS have unlocked V850. Can protocol is different in Renault and Nissan. But maybe full flash with bootloader from Kangoo BMS can help for reverse engineering)

In Ukraine my friend start change chip in Leaf BMS for custom, long time ago (maybe 6 year ago), and now he have more than 300 OEM chip))

Super, there is different candb in the firmware, but if hw is simmilar to nissan (probably yes) this might be helpful.
 
Last edited:
I have, but I am in Ukraine) Maybe I found time to try read MCU flash. I have vvdi2 programmer, need check is it supposed V850.
You need only FTDI or another usb to serial interface and Renesas flash programmer app for connection to serial bootloader in the chip.
@safetyuggs can share with you pinnout for connection. I dont have any LBC for testing but its working , tested with another ecu. If there is no read lock you can dump complete flash.
 
Last edited:
Back
Top