Author Topic: Trimble Thunderbolt firmware dumps and script  (Read 482 times)

0 Members and 1 Guest are viewing this topic.

Offline bdbbdbTopic starter

  • Newbie
  • Posts: 8
  • Country: us
Trimble Thunderbolt firmware dumps and script
« on: October 04, 2026, 06:52:59 pm »
Thought I would share some progress I've made on poking around at Trimble Thunderbolt devices.

I've got a red-label Tbolt, S/N 12176159 DoM 03/12/2001. It has application 2.20 on it and one of the 37265 Trimble-branded OCXOs in it.

I've managed to extract the firmware from my unit non-destructively. I've attached the firmware dumps here, since they don't seem to be out in the wild anywhere I can find. One of them is a dump of the bootloader in the mask ROM of the main CPU, the other is a dump of the Am29F400 external flash chip. On the red-label Tbolts at least, the main CPU is a MC68330/MC68340 derivative with some custom hardware blocks onboard.

I noticed that Trimble released two similar products around this era, the Palisade and the Lassen. Both of these have firmware updates and flash tools available; looking at these tools showed a pretty similar pattern in how they were programmed - there's a TSIP packet (0x1E 0x54) that will cause the unit to jump to a ROM-monitor-like interface. The red-label Thunderbolt behaves like a Palisade device. It has a few commands which can read, write, and jump to arbitrary addresses. You can dump the flash, or upload a program that will erase and write to the onboard flash and jump to it - this is how the Palisade's flash tool works.

The command and monitor is similar on the Lassen, though it has a different CPU (another Trimble ASIC with an Epson C33 core) and a different TSIP packet to trigger it. I am curious whether the gold Thunderbolts have the Lassen-style CPU. From squinting at the markings in eBay photos... maybe? I don't have one to compare with, though. If anyone is willing to try the scripts below against a gold Thunderbolt, particularly one running firmware 3.0, I'd appreciate it.

These Python scripts will probe for both styles of bootloader, and dump the bootrom and flash from Palisade-style boards:

bootloader probe script - https://gist.github.com/berg/186e46234e0d041dd7f693c3087e225e
dump script - https://gist.github.com/berg/243c9912016051b8e378210af4f8259d

These run easily from `uv run` and take a pyserial-style name for the serial port.

Note that while I do not have any expectation that this will break your device, you do so at your own risk. You will need to reboot your device after/between running the scripts (this may be undesirable for you!)
 

Online perdrix

  • Frequent Contributor
  • **
  • Posts: 817
  • Country: gb
Re: Trimble Thunderbolt firmware dumps and script
« Reply #1 on: October 05, 2026, 12:31:34 am »
So when are we going to see the reverse engineered C code (with help from you f(r)iendly local LLM)?   :)

David
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf

 

-->