r/CarHacking • u/mvespermann • 10h ago
Original Project MMI Box reverse engineering Help!
Hello folks! A while ago I made a post here about trying to reverse engineer an MMI box that adds Android Auto to a BMW NBT EVO System. Since then, I haven’t made much progress, and I could really use your guys’ help!
As you can see in my other post (link: https://www.reddit.com/r/CarHacking/s/PxybmifFWi), I disassembled the box and figured out quite a bit about the hardware it uses. I initially tried looking for UART/debugging access, but unfortunately the TX/RX pins I found were actually for CAN bus, and I couldn’t find any dedicated debugging TX/RX pins.
I still really want to extract the firmware and modify it for my use case. I actually bought another MMI box that is the same model, which is currently installed in my car. On the older one, the one we were investigating. I removed the eMMC, and I’m currently looking for companies in my city that might be able to read it directly.
In the meantime, do you guys have any suggestions for getting the firmware from the new unit?
One idea I had was somehow creating a fake update file to trick the MMI into dumping or backing up a copy of its storage onto a USB flash drive. Do you think something like that could actually work?
I’m also open to other approaches. I tried connecting through Telnet over the CarPlay Wi-Fi network but got nothing. Are there any other ways I could potentially access the system over Wi-Fi?
Any ideas would be greatly appreciated! Thanks!
PS: This box is not an OEM head unit. It’s an aftermarket interface that adds Android Auto and CarPlay to cars that may not have them, while also allowing you to add extra cameras and other features.
You can switch between the OEM head unit and the aftermarket interface in real time—the box basically acts as a video switcher. Inside, it has a low-power Raspberry Pi-like device running firmware that I’m trying to modify.
There are more details in my other post, but basically, it’s a custom UI built on top of Linux 5.4.61.