Login Register

Vida CEM swapping

A mid-size luxury crossover SUV, the Volvo XC90 made its debut in 2002 at the Detroit Motor Show. Recognized for its safety, practicality, and comfort, the XC90 is a popular vehicle around the world. The XC90 proved to be very popular, and very good for Volvo's sales numbers, since its introduction in model year 2003 (North America). P2 platform.
Post Reply
Yariy
Posts: 41
Joined: 1 July 2024
Year and Model: XC90
Location: Moskow
Has thanked: 13 times
Been thanked: 10 times

Re: Vida CEM swapping

Post by Yariy »

I agree, there are very few cars with the CEMB unit left. We do not take these cars for diagnostics because of their age. But I was interested in reverse engineering and the lack of a tool for this block, so I decided to try my hand at it.

vtl
Posts: 4723
Joined: 16 August 2012
Year and Model: 2005 XC70
Location: Boston
Has thanked: 114 times
Been thanked: 603 times

Post by vtl »

Curiosity drives the progress.

Yariy
Posts: 41
Joined: 1 July 2024
Year and Model: XC90
Location: Moskow
Has thanked: 13 times
Been thanked: 10 times

Post by Yariy »

WhizzMan wrote: ↑18 Jul 2025, 06:49
Treur wrote: ↑18 Jul 2025, 06:33
The problem is that Io-terminal and others cannot load SBL with a pin other than FF.
So even if you know the PIN, you cannot modify the SBL to work with a different PIN?
Would below scenario work? Is it even useful or would just using other method be just as fast/complex?

1. Read the PIN via other method
2. "store" the original PIN
3. write just the pin to FF (let all other data remain)
4. Load SBL, read entire 512 kB.
5. write original PIN back.
Yes it will work

Treur
Posts: 126
Joined: 16 November 2024
Year and Model: 2007 V70
Location: Estonia
Has thanked: 3 times
Been thanked: 6 times

Post by Treur »

Yariy wrote: ↑18 Jul 2025, 08:17
Treur wrote: ↑18 Jul 2025, 06:26
Yariy wrote: ↑17 Jul 2025, 14:32 And that's why I'm leaning towards SBL for CEMB, because for example, in diagnostic mode, you can read the entire flash (512Kbytes), but it takes at least 20 minutes, and reading from the address in programm mode takes many times more. My test SBL reads the flash in 1 minute and 20 seconds, but so far without any checksums, etc. Well, it doesn't matter yet.
Π’Π°ΠΊ бСсполСзно Ρ‡ΠΈΡ‚Π°Ρ‚ΡŒ Π² диагностичСской сСссии, Π½Ρƒ ΠΏΡ€ΠΎΡ‡ΠΈΡ‚Π°Π»ΠΈ, Π° Π·Π°ΠΏΠΈΡΠ°Ρ‚ΡŒ всё Ρ€Π°Π²Π½ΠΎ Π² Π½Π΅ΠΉ Π½Π΅ ΠΌΠΎΠΆΠ΅ΠΌ. Π’ΠΎΡ‚ Ссли ΠΌΡ‹ ΠΌΠΎΠΆΠ΅ΠΌ ΠΏΠ΅Ρ€Π΅ΠΏΠΈΡΠ°Ρ‚ΡŒ кусок с ΠΏΠΈΠ½ΠΎΠΌ/ΠΏΡ€ΠΎΠΏΠ°Ρ‚Ρ‡ΠΈΡ‚ΡŒ ΠΎΡΠ½ΠΎΠ²Π½ΡƒΡŽ ΠΏΡ€ΠΎΠ³Ρ€Π°ΠΌΠΌΡƒ ΠΈ PBL, Ρ‚ΠΎ Π±Ρ‹Π» Π±Ρ‹ смысл. Π― Π½Π΅ особо Π΄Π°ΠΆΠ΅ Ρ€Π°ΡΡΠΌΠ°Ρ‚Ρ€ΠΈΠ²Π°ΡŽ ΡƒΠΆΠ΅ этот ΠΌΠ΅Ρ‚Π°Π»Π»ΠΎΠ»ΠΎΠΌ ΠΈΠ±ΠΎ Ρ‚Π°Ρ‡ΠΊΠΈ Π½Π° Π½ΠΈΡ… ΡƒΠΆΠ΅ Π² стадии вымирания.
По части Ρ‚Π΅Ρ€ΠΌΠΈΠ½Π°Π»Π° - ΠΎΠ½ΠΈ Π΄Π°Π»Π΅ΠΊΠΎ Π½Π΅ всё вывСсили Π½Π° сайтС. Π― ΡƒΠΆΠ΅ ΠΏΠΎΠΈΠΌΠ΅Π» ΠΈΡ… SBL, Π½ΠΎ CEM Π΅Π³ΠΎ ΠΏΡ€ΠΈΠ½ΠΈΠΌΠ°Π΅Ρ‚ Ρ‚ΠΎΠ»ΡŒΠΊΠΎ ΠΏΡ€ΠΈ ΠΏΠΈΠ½ FF, ΠΈ я чСстно Ρ‚ΠΎ говоря Π½Π΅ ΠΎΡ‡Π΅Π½ΡŒ понимаю ΠΌΡ‹ΡˆΠ»Π΅Π½ΠΈΠ΅ швСдов - ΠΌΡ‹ пишСм Ρ‚ΠΎΠ»ΡŒΠΊΠΎ Π½ΠΎΠ²Ρ‹ΠΉ Π±Π»ΠΎΠΊ. Π’ΡƒΡ‚ роТдаСтся Π»ΠΎΠ³ΠΈΡ‡Π½Ρ‹ΠΉ вопрос - ΠΏΡ€ΠΈΠ΅Ρ…Π°Π» ΠΊ Π΄ΠΈΠ»Π΅Ρ€Ρƒ ΠΊΠ»ΠΈΠ΅Π½Ρ‚ Π½Π° скаТСм дооснащСниС ΠΈΠΈΠΈΠΈ????
Honestly, I haven't figured out what the SBL download function is used for in CEMB. Maybe a dump of a brand new CEMB will clarify things. The configuration lies in an unprotected area and you can change it knowing the current Pin code and not necessarily FF. The protected area contains the pin code, keys, synchronization, etc.
I don't get it either. Especially considering all the references in Vida about software numbers for downloading

Yariy
Posts: 41
Joined: 1 July 2024
Year and Model: XC90
Location: Moskow
Has thanked: 13 times
Been thanked: 10 times

Post by Yariy »

Treur wrote: ↑18 Jul 2025, 08:43
Yariy wrote: ↑18 Jul 2025, 08:17
Treur wrote: ↑18 Jul 2025, 06:26
Π’Π°ΠΊ бСсполСзно Ρ‡ΠΈΡ‚Π°Ρ‚ΡŒ Π² диагностичСской сСссии, Π½Ρƒ ΠΏΡ€ΠΎΡ‡ΠΈΡ‚Π°Π»ΠΈ, Π° Π·Π°ΠΏΠΈΡΠ°Ρ‚ΡŒ всё Ρ€Π°Π²Π½ΠΎ Π² Π½Π΅ΠΉ Π½Π΅ ΠΌΠΎΠΆΠ΅ΠΌ. Π’ΠΎΡ‚ Ссли ΠΌΡ‹ ΠΌΠΎΠΆΠ΅ΠΌ ΠΏΠ΅Ρ€Π΅ΠΏΠΈΡΠ°Ρ‚ΡŒ кусок с ΠΏΠΈΠ½ΠΎΠΌ/ΠΏΡ€ΠΎΠΏΠ°Ρ‚Ρ‡ΠΈΡ‚ΡŒ ΠΎΡΠ½ΠΎΠ²Π½ΡƒΡŽ ΠΏΡ€ΠΎΠ³Ρ€Π°ΠΌΠΌΡƒ ΠΈ PBL, Ρ‚ΠΎ Π±Ρ‹Π» Π±Ρ‹ смысл. Π― Π½Π΅ особо Π΄Π°ΠΆΠ΅ Ρ€Π°ΡΡΠΌΠ°Ρ‚Ρ€ΠΈΠ²Π°ΡŽ ΡƒΠΆΠ΅ этот ΠΌΠ΅Ρ‚Π°Π»Π»ΠΎΠ»ΠΎΠΌ ΠΈΠ±ΠΎ Ρ‚Π°Ρ‡ΠΊΠΈ Π½Π° Π½ΠΈΡ… ΡƒΠΆΠ΅ Π² стадии вымирания.
По части Ρ‚Π΅Ρ€ΠΌΠΈΠ½Π°Π»Π° - ΠΎΠ½ΠΈ Π΄Π°Π»Π΅ΠΊΠΎ Π½Π΅ всё вывСсили Π½Π° сайтС. Π― ΡƒΠΆΠ΅ ΠΏΠΎΠΈΠΌΠ΅Π» ΠΈΡ… SBL, Π½ΠΎ CEM Π΅Π³ΠΎ ΠΏΡ€ΠΈΠ½ΠΈΠΌΠ°Π΅Ρ‚ Ρ‚ΠΎΠ»ΡŒΠΊΠΎ ΠΏΡ€ΠΈ ΠΏΠΈΠ½ FF, ΠΈ я чСстно Ρ‚ΠΎ говоря Π½Π΅ ΠΎΡ‡Π΅Π½ΡŒ понимаю ΠΌΡ‹ΡˆΠ»Π΅Π½ΠΈΠ΅ швСдов - ΠΌΡ‹ пишСм Ρ‚ΠΎΠ»ΡŒΠΊΠΎ Π½ΠΎΠ²Ρ‹ΠΉ Π±Π»ΠΎΠΊ. Π’ΡƒΡ‚ роТдаСтся Π»ΠΎΠ³ΠΈΡ‡Π½Ρ‹ΠΉ вопрос - ΠΏΡ€ΠΈΠ΅Ρ…Π°Π» ΠΊ Π΄ΠΈΠ»Π΅Ρ€Ρƒ ΠΊΠ»ΠΈΠ΅Π½Ρ‚ Π½Π° скаТСм дооснащСниС ΠΈΠΈΠΈΠΈ????
Honestly, I haven't figured out what the SBL download function is used for in CEMB. Maybe a dump of a brand new CEMB will clarify things. The configuration lies in an unprotected area and you can change it knowing the current Pin code and not necessarily FF. The protected area contains the pin code, keys, synchronization, etc.
I don't get it either. Especially considering all the references in Vida about software numbers for downloading
In Vida, I saw the vbf number for download only when replacing with a new block. Are there vbf CEMB numbers available for download, for example, during retrofitting?

Yariy
Posts: 41
Joined: 1 July 2024
Year and Model: XC90
Location: Moskow
Has thanked: 13 times
Been thanked: 10 times

Post by Yariy »

Treur wrote: ↑18 Jul 2025, 06:26
Yariy wrote: ↑17 Jul 2025, 14:32 And that's why I'm leaning towards SBL for CEMB, because for example, in diagnostic mode, you can read the entire flash (512Kbytes), but it takes at least 20 minutes, and reading from the address in programm mode takes many times more. My test SBL reads the flash in 1 minute and 20 seconds, but so far without any checksums, etc. Well, it doesn't matter yet.
Π’Π°ΠΊ бСсполСзно Ρ‡ΠΈΡ‚Π°Ρ‚ΡŒ Π² диагностичСской сСссии, Π½Ρƒ ΠΏΡ€ΠΎΡ‡ΠΈΡ‚Π°Π»ΠΈ, Π° Π·Π°ΠΏΠΈΡΠ°Ρ‚ΡŒ всё Ρ€Π°Π²Π½ΠΎ Π² Π½Π΅ΠΉ Π½Π΅ ΠΌΠΎΠΆΠ΅ΠΌ. Π’ΠΎΡ‚ Ссли ΠΌΡ‹ ΠΌΠΎΠΆΠ΅ΠΌ ΠΏΠ΅Ρ€Π΅ΠΏΠΈΡΠ°Ρ‚ΡŒ кусок с ΠΏΠΈΠ½ΠΎΠΌ/ΠΏΡ€ΠΎΠΏΠ°Ρ‚Ρ‡ΠΈΡ‚ΡŒ ΠΎΡΠ½ΠΎΠ²Π½ΡƒΡŽ ΠΏΡ€ΠΎΠ³Ρ€Π°ΠΌΠΌΡƒ ΠΈ PBL, Ρ‚ΠΎ Π±Ρ‹Π» Π±Ρ‹ смысл. Π― Π½Π΅ особо Π΄Π°ΠΆΠ΅ Ρ€Π°ΡΡΠΌΠ°Ρ‚Ρ€ΠΈΠ²Π°ΡŽ ΡƒΠΆΠ΅ этот ΠΌΠ΅Ρ‚Π°Π»Π»ΠΎΠ»ΠΎΠΌ ΠΈΠ±ΠΎ Ρ‚Π°Ρ‡ΠΊΠΈ Π½Π° Π½ΠΈΡ… ΡƒΠΆΠ΅ Π² стадии вымирания.
По части Ρ‚Π΅Ρ€ΠΌΠΈΠ½Π°Π»Π° - ΠΎΠ½ΠΈ Π΄Π°Π»Π΅ΠΊΠΎ Π½Π΅ всё вывСсили Π½Π° сайтС. Π― ΡƒΠΆΠ΅ ΠΏΠΎΠΈΠΌΠ΅Π» ΠΈΡ… SBL, Π½ΠΎ CEM Π΅Π³ΠΎ ΠΏΡ€ΠΈΠ½ΠΈΠΌΠ°Π΅Ρ‚ Ρ‚ΠΎΠ»ΡŒΠΊΠΎ ΠΏΡ€ΠΈ ΠΏΠΈΠ½ FF, ΠΈ я чСстно Ρ‚ΠΎ говоря Π½Π΅ ΠΎΡ‡Π΅Π½ΡŒ понимаю ΠΌΡ‹ΡˆΠ»Π΅Π½ΠΈΠ΅ швСдов - ΠΌΡ‹ пишСм Ρ‚ΠΎΠ»ΡŒΠΊΠΎ Π½ΠΎΠ²Ρ‹ΠΉ Π±Π»ΠΎΠΊ. Π’ΡƒΡ‚ роТдаСтся Π»ΠΎΠ³ΠΈΡ‡Π½Ρ‹ΠΉ вопрос - ΠΏΡ€ΠΈΠ΅Ρ…Π°Π» ΠΊ Π΄ΠΈΠ»Π΅Ρ€Ρƒ ΠΊΠ»ΠΈΠ΅Π½Ρ‚ Π½Π° скаТСм дооснащСниС ΠΈΠΈΠΈΠΈ????
It is interesting to take a look at SBL ioterminal. I am most interested in whether the PBL recording function is included in it. At the hardware level, I have not yet found out if it is possible to remove the write lock on the loader area.

Treur
Posts: 126
Joined: 16 November 2024
Year and Model: 2007 V70
Location: Estonia
Has thanked: 3 times
Been thanked: 6 times

Post by Treur »

Yariy wrote: ↑18 Jul 2025, 11:03
Treur wrote: ↑18 Jul 2025, 06:26
Yariy wrote: ↑17 Jul 2025, 14:32 And that's why I'm leaning towards SBL for CEMB, because for example, in diagnostic mode, you can read the entire flash (512Kbytes), but it takes at least 20 minutes, and reading from the address in programm mode takes many times more. My test SBL reads the flash in 1 minute and 20 seconds, but so far without any checksums, etc. Well, it doesn't matter yet.
Π’Π°ΠΊ бСсполСзно Ρ‡ΠΈΡ‚Π°Ρ‚ΡŒ Π² диагностичСской сСссии, Π½Ρƒ ΠΏΡ€ΠΎΡ‡ΠΈΡ‚Π°Π»ΠΈ, Π° Π·Π°ΠΏΠΈΡΠ°Ρ‚ΡŒ всё Ρ€Π°Π²Π½ΠΎ Π² Π½Π΅ΠΉ Π½Π΅ ΠΌΠΎΠΆΠ΅ΠΌ. Π’ΠΎΡ‚ Ссли ΠΌΡ‹ ΠΌΠΎΠΆΠ΅ΠΌ ΠΏΠ΅Ρ€Π΅ΠΏΠΈΡΠ°Ρ‚ΡŒ кусок с ΠΏΠΈΠ½ΠΎΠΌ/ΠΏΡ€ΠΎΠΏΠ°Ρ‚Ρ‡ΠΈΡ‚ΡŒ ΠΎΡΠ½ΠΎΠ²Π½ΡƒΡŽ ΠΏΡ€ΠΎΠ³Ρ€Π°ΠΌΠΌΡƒ ΠΈ PBL, Ρ‚ΠΎ Π±Ρ‹Π» Π±Ρ‹ смысл. Π― Π½Π΅ особо Π΄Π°ΠΆΠ΅ Ρ€Π°ΡΡΠΌΠ°Ρ‚Ρ€ΠΈΠ²Π°ΡŽ ΡƒΠΆΠ΅ этот ΠΌΠ΅Ρ‚Π°Π»Π»ΠΎΠ»ΠΎΠΌ ΠΈΠ±ΠΎ Ρ‚Π°Ρ‡ΠΊΠΈ Π½Π° Π½ΠΈΡ… ΡƒΠΆΠ΅ Π² стадии вымирания.
По части Ρ‚Π΅Ρ€ΠΌΠΈΠ½Π°Π»Π° - ΠΎΠ½ΠΈ Π΄Π°Π»Π΅ΠΊΠΎ Π½Π΅ всё вывСсили Π½Π° сайтС. Π― ΡƒΠΆΠ΅ ΠΏΠΎΠΈΠΌΠ΅Π» ΠΈΡ… SBL, Π½ΠΎ CEM Π΅Π³ΠΎ ΠΏΡ€ΠΈΠ½ΠΈΠΌΠ°Π΅Ρ‚ Ρ‚ΠΎΠ»ΡŒΠΊΠΎ ΠΏΡ€ΠΈ ΠΏΠΈΠ½ FF, ΠΈ я чСстно Ρ‚ΠΎ говоря Π½Π΅ ΠΎΡ‡Π΅Π½ΡŒ понимаю ΠΌΡ‹ΡˆΠ»Π΅Π½ΠΈΠ΅ швСдов - ΠΌΡ‹ пишСм Ρ‚ΠΎΠ»ΡŒΠΊΠΎ Π½ΠΎΠ²Ρ‹ΠΉ Π±Π»ΠΎΠΊ. Π’ΡƒΡ‚ роТдаСтся Π»ΠΎΠ³ΠΈΡ‡Π½Ρ‹ΠΉ вопрос - ΠΏΡ€ΠΈΠ΅Ρ…Π°Π» ΠΊ Π΄ΠΈΠ»Π΅Ρ€Ρƒ ΠΊΠ»ΠΈΠ΅Π½Ρ‚ Π½Π° скаТСм дооснащСниС ΠΈΠΈΠΈΠΈ????
It is interesting to take a look at SBL ioterminal. I am most interested in whether the PBL recording function is included in it. At the hardware level, I have not yet found out if it is possible to remove the write lock on the loader area.
Do you have a Telegram?

Yariy
Posts: 41
Joined: 1 July 2024
Year and Model: XC90
Location: Moskow
Has thanked: 13 times
Been thanked: 10 times

Post by Yariy »

Treur wrote: ↑18 Jul 2025, 11:31
Yariy wrote: ↑18 Jul 2025, 11:03
Treur wrote: ↑18 Jul 2025, 06:26
Π’Π°ΠΊ бСсполСзно Ρ‡ΠΈΡ‚Π°Ρ‚ΡŒ Π² диагностичСской сСссии, Π½Ρƒ ΠΏΡ€ΠΎΡ‡ΠΈΡ‚Π°Π»ΠΈ, Π° Π·Π°ΠΏΠΈΡΠ°Ρ‚ΡŒ всё Ρ€Π°Π²Π½ΠΎ Π² Π½Π΅ΠΉ Π½Π΅ ΠΌΠΎΠΆΠ΅ΠΌ. Π’ΠΎΡ‚ Ссли ΠΌΡ‹ ΠΌΠΎΠΆΠ΅ΠΌ ΠΏΠ΅Ρ€Π΅ΠΏΠΈΡΠ°Ρ‚ΡŒ кусок с ΠΏΠΈΠ½ΠΎΠΌ/ΠΏΡ€ΠΎΠΏΠ°Ρ‚Ρ‡ΠΈΡ‚ΡŒ ΠΎΡΠ½ΠΎΠ²Π½ΡƒΡŽ ΠΏΡ€ΠΎΠ³Ρ€Π°ΠΌΠΌΡƒ ΠΈ PBL, Ρ‚ΠΎ Π±Ρ‹Π» Π±Ρ‹ смысл. Π― Π½Π΅ особо Π΄Π°ΠΆΠ΅ Ρ€Π°ΡΡΠΌΠ°Ρ‚Ρ€ΠΈΠ²Π°ΡŽ ΡƒΠΆΠ΅ этот ΠΌΠ΅Ρ‚Π°Π»Π»ΠΎΠ»ΠΎΠΌ ΠΈΠ±ΠΎ Ρ‚Π°Ρ‡ΠΊΠΈ Π½Π° Π½ΠΈΡ… ΡƒΠΆΠ΅ Π² стадии вымирания.
По части Ρ‚Π΅Ρ€ΠΌΠΈΠ½Π°Π»Π° - ΠΎΠ½ΠΈ Π΄Π°Π»Π΅ΠΊΠΎ Π½Π΅ всё вывСсили Π½Π° сайтС. Π― ΡƒΠΆΠ΅ ΠΏΠΎΠΈΠΌΠ΅Π» ΠΈΡ… SBL, Π½ΠΎ CEM Π΅Π³ΠΎ ΠΏΡ€ΠΈΠ½ΠΈΠΌΠ°Π΅Ρ‚ Ρ‚ΠΎΠ»ΡŒΠΊΠΎ ΠΏΡ€ΠΈ ΠΏΠΈΠ½ FF, ΠΈ я чСстно Ρ‚ΠΎ говоря Π½Π΅ ΠΎΡ‡Π΅Π½ΡŒ понимаю ΠΌΡ‹ΡˆΠ»Π΅Π½ΠΈΠ΅ швСдов - ΠΌΡ‹ пишСм Ρ‚ΠΎΠ»ΡŒΠΊΠΎ Π½ΠΎΠ²Ρ‹ΠΉ Π±Π»ΠΎΠΊ. Π’ΡƒΡ‚ роТдаСтся Π»ΠΎΠ³ΠΈΡ‡Π½Ρ‹ΠΉ вопрос - ΠΏΡ€ΠΈΠ΅Ρ…Π°Π» ΠΊ Π΄ΠΈΠ»Π΅Ρ€Ρƒ ΠΊΠ»ΠΈΠ΅Π½Ρ‚ Π½Π° скаТСм дооснащСниС ΠΈΠΈΠΈΠΈ????
It is interesting to take a look at SBL ioterminal. I am most interested in whether the PBL recording function is included in it. At the hardware level, I have not yet found out if it is possible to remove the write lock on the loader area.
Do you have a Telegram?
See the mailbox

dikidera
Posts: 1304
Joined: 15 August 2022
Year and Model: S60 2005
Location: Galaxy far far away
Has thanked: 67 times
Been thanked: 175 times

Post by dikidera »

Please try the J2534 tool, for now works on Hispeed bus(so do not choose anything else), be sure to click 29 bit extended ID. Platform also does nothing useful quite yet. Sources in the near future when everything works correctly.

I am happy with the way the monitor works, please test with Mongoose and if someone can with DiCE.
Attachments
j2534.7z
(8.4 MiB) Downloaded 119 times

bosse
Posts: 19
Joined: 15 January 2021
Year and Model: V50 -11
Location: Limmared
Has thanked: 8 times
Been thanked: 1 time

Post by bosse »

Waiting for page 400...
Follow from start πŸ˜€πŸ‘

Post Reply
  • Similar Topics
    Replies
    Views
    Last post