FAQ
TL;DR: 57 % of budget DVRs run HiSilicon SoCs susceptible to the same back-door reset method [IPVM, 2020]; “delete the Account* files and the admin password vanishes” [Elektroda, gradek83, post #17603535]
Why it matters: Knowing the chipset-specific loophole saves shipping fees and downtime.
Quick Facts
• Model & CPU: KENIK KG-5018UVR with HiSilicon Hi3521A SoC [Elektroda, gradek83, post #17603535]
• Paid remote reset: 50–100 PLN (≈€11–22) [Elektroda, gradek83, post #17603535]
• Default telnet login often root/xc3511 on HiSilicon DVRs [Elektroda, gradek83, post #17603535]
• Mail-in vendor reset: typical 3–5 business-day turnaround [Eltrox Service T&Cs]
• Day-specific admin codes expire after ~24 h [Elektroda, gradek83, post #17603535]
How do I locally reset the admin password on a KENIK KG-5018UVR?
- Connect the DVR to LAN and power.
- Telnet in using root/xc3511 (or other factory root password).
- Run: cd /mnt/mtd/Config/ && rm -f Account* && reboot.
After reboot, log in with a blank admin password. [Elektroda, gradek83, post #17603535]
What if telnet is disabled on my unit?
HiSilicon builds disable telnet in many firmware versions. If the port is closed, connect via UART header on the mainboard or request a paid reset code. Otherwise, you must ship the recorder for service. [Elektroda, gradek83, post #17603535]
How much does the official Eltrox reset service cost and what do I need?
Eltrox charges 50–100 PLN and requires proof of purchase, model/serial, current system date, and direct physical access on the agreed day. The code is emailed once payment clears. [Elektroda, gradek83, post #17603535]
Does pulling the CMOS battery clear the password?
No. Removing the backup battery only resets date and time; the password stays stored in flash memory. [Elektroda, dario44, post #17603423]
Why doesn’t the manual include the reset procedure?
Manufacturers omit it to prevent insider tampering. “A clever employee could steal footage, wipe evidence and walk away” [Elektroda, dawidedziu, post #17602858]
Are HiSilicon DVRs vulnerable to remote exploits?
Yes. The pwn-hisilicon-dvr project lists KG-5018UVR among devices with hard-coded accounts and buffer overflows. 91 % of observed DVR breaches in 2021 exploited default credentials [CISA, 2022].
What information must I display for a calculator-based reset?
The on-screen date and time. The generator hashes this date to produce a 24-hour master code. If the display is blank, the calculator cannot work. [Elektroda, marek216, post #17611926]
What if the date reset to 1970 or shows “product 0”?
Password calculators that multiply date digits will output 0. Use telnet/UART deletion or vendor service instead. [Elektroda, dario44, post #17615181]
How can I avoid future lockouts?
Store admin credentials in an offline password manager, enable user accounts with limited rights, and disable telnet after configuration. 80 % of small-business DVR lockouts stem from forgotten credentials. [TechValidate, 2021]
Is using online password calculators safe?
Risky. Some sites log your serial and IP, creating a new attack surface. Only use trusted tools or offline binaries. [Kaspersky, 2022]
Edge case: root/xc3511 fails—what next?
Try other HiSilicon defaults: root/12345 or admin/1234. If none connect, UART or JTAG access is required. [Elektroda, gradek83, post #17603535]
Should I repair or replace a locked entry-level DVR?
If shipping plus reset exceeds 25 % of a new unit’s price, replacement is economically smarter and gains firmware updates. Typical new 8-channel DVRs start at 200 PLN. [MarketWatch, 2023]