UNICIM VN700 / VN700+ & ZLT X21 (NEW)

ZLT X21 / X21G — Unlock, Engineering Access, SIM Setup & Security Guide
This guide documents a practical method for gaining additional administrative/engineering access on the ZLT X21 / X21G and then configuring it for normal use with a SIM card.
Important: X21 and X21G firmware packages are hardware/model specific. Do not flash a firmware package just because it says X21. Verify that it is specifically for your X21G hardware. An incorrect firmware can brick the router.


⸻


1. What this procedure actually unlocks
There are several different meanings of “unlock” on the X21:
Web administrator access
Hidden/engineering settings
ADB access
Root shell access
Ability to inspect and modify system configuration
SIM/APN/network configuration
These are different from a guaranteed carrier/baseband unlock.
Therefore, don’t advertise this as a guaranteed method for removing every possible carrier restriction. It is more accurate to describe it as:
Unlocking additional administrative/engineering access and gaining root ADB access on supported X21/X21G firmware.


⸻


2. Before starting
You need:
ZLT X21/X21G
A Mac or Windows computer
USB/network access to the router
Router web interface
ADB platform-tools if you want root shell access
A firmware package specifically matching the X21G hardware
The router’s normal web address in this setup is:
You do not have permission to view the full content of this post. Log in or register now.
The exact menus can vary depending on firmware.


⸻


3. Firmware — the important part
One firmware package used during the investigation was:
X21G_1.10.23_usr_UN2020C_20211116_normal_update.swu
The important point is not simply the version number. The package must match the X21G hardware.
After flashing, the device may show something that looks confusing:
Software Version: 1.16.1.4
TZ Version: 1.10.23
This does not necessarily mean the firmware flash failed.
The X21 has multiple software components. The displayed “Software Version”, TZ version, indoor-unit firmware and modem firmware are not necessarily the same thing.
For example, an X21G can report:
Model: ZLT X21
Hardware: TZ7.823.407
TZ Version: 1.10.23
Indoor Unit firmware: X21G_V1.8.11
Modem: Orca/udx710 platform
Therefore, record all version fields before deciding that a firmware change worked or failed.


⸻


4. Exposing the hidden engineering menu
After logging into the router’s web interface:
Open the router web interface.
Open the browser developer tools.
Use the Console.
Enter:
Page.level=1
Press Enter.
On compatible firmware, this changes the web interface level and exposes additional engineering/system settings.
If it returns:
1
the command was accepted.
Refresh/open the router interface again if necessary.


⸻


5. Hidden System Settings
After Page.level=1, additional settings can appear under:
Management → System Settings
Depending on firmware, you may see items such as:
Change Password
Change Username
Time Settings
Restore Factory Settings
Import/Export Configuration
Telnet Switch
Module LOG switch
ADB Switch
SFP IPA Switch
COMMLOG Backup Setting
Abnormal Automatic Restart Switch
TR069 LOG Switch
YOCTO LOG Switch
The exact list varies between firmware versions.


⸻


6. Enable ADB
On firmware where the hidden ADB Switch is available:
Management → System Settings → ADB Switch
Enable ADB and save/apply the setting.
The router can then expose ADB on:
192.168.70.1:5555
Do not enable Telnet simply because it is available. ADB was sufficient for the root-shell work.


⸻


7. Connect from a Mac
Download Android platform-tools and place the folder somewhere convenient.
For example:
cd ~/Downloads/platform-tools
Check ADB:
./adb version
Then connect:
./adb connect 192.168.70.1:5555
If the connection succeeds:
./adb shell
On the successfully unlocked X21/X21G setup, this produced a root shell similar to:
root@udx710-module-pi:/ #
That means you have root-level shell access to the router’s underlying Linux environment.


⸻


8. Setting the web superadmin password
From the root ADB shell, the mdlcfg utility can be used on compatible firmware.
The relevant configuration commands are:
mdlcfg -f SYS_WEB_SUPER_PWD_RULE="1"
mdlcfg -a SYS_WEB_SUPER_PWD_RULE="1"

mdlcfg -f SYS_SUPER_LOGIN_PWD="<YOUR-OWN-PASSWORD>"
mdlcfg -a SYS_SUPER_LOGIN_PWD="<YOUR-OWN-PASSWORD>"

mdlcfg -c
Replace:
<YOUR-OWN-PASSWORD>
with a strong password of your choice.
Never post your actual password in a public forum.
After applying the configuration, the web interface can accept the superadmin account on firmware that supports this configuration.


⸻


9. A note about changing the username
Changing the visible administrator username and changing the underlying superadmin account are not necessarily the same thing.
On some X21 firmware, the web interface allows a username to be changed, but the underlying superadmin configuration may continue to use:
superadmin
Therefore, don’t assume a successful “Change Username” message means that every internal administrator account has been renamed.
The important thing is to establish a working administrator account and a strong password.


⸻


10. SIM / APN configuration
Once administrative access is available, configure the SIM through the normal network settings.
For a different carrier:
Insert the SIM.
Check SIM status.
Check network registration.
Select the appropriate network mode.
Configure the carrier’s APN.
Save/apply.
Reconnect the mobile data connection.
If the router shows a mobile IP but there is no Internet, check:
APN
default route/gateway
DNS
network registration
selected network mode
carrier compatibility
A registered SIM does not automatically mean that Internet routing is working.


⸻


11. Recommended 4G-only configuration
If the local area has poor or no useful 5G coverage, there is no reason to force 5G.
Under the network settings:
Network Mode → 4G Only
This avoids the router unnecessarily looking for 5G when the usable network is LTE.


⸻


12. WAN Mode
Under:
Network Settings → WAN Mode
Available choices can include:
Mobile Network Mode
Wired Network Mode
WiFi-2.4G Network Mode
WiFi-5G Network Mode
Mobile/Wired Network Mode
For a router being used with a SIM as the Internet connection:
WAN Mode → Mobile Network Mode


⸻


13. 4/5G Display Solution
Some X21 firmware has:
Internet Function → 4/5G Display Solution
The choices can be:
A
B
C
D
These settings determine how the interface labels/displays different LTE/NSA/NR states.
They do not directly increase cellular signal strength.
If the router is being used as a 4G-only device, changing this setting is generally unnecessary.


⸻


14. UE Capability Configuration
Under:
Internet Function → UE Configuration → UE Capability Config
The following options were found:
SRS Antenna Rotation → ON
TX Space MIMO Switch → ON
Recommended:
SRS Antenna Rotation → ON
TX Space MIMO → ON
These should normally be left enabled rather than disabling modem radio capabilities without a specific reason.
Under:
UE Configuration → Other Configuration
If the switch is already OFF, leave it OFF unless you know exactly what the option does.


⸻


15. Security configuration
After obtaining root/engineering access, do not leave debugging services enabled unnecessarily.
Recommended final state:
Setting
Recommended
ADB
OFF after finishing
Telnet
OFF
WPS
OFF
UPnP
OFF
DMZ
OFF
DDoS Protection
ON
Automatic Firmware Update
OFF if you want to control firmware changes
Port Forwarding
No unnecessary rules
ACL Firewall
No unnecessary rules
Remote Web Port
Leave at 443 unless there is a specific reason to change it
Strong admin password
YES
Important
Do not assume:
TR069 LOG Switch
YOCTO LOG Switch
are the same thing as the actual remote-management service.
They are logging-related settings. Don’t randomly disable them simply because their names contain TR069 or YOCTO.


⸻


16. Firewall settings
Useful safe defaults:
DMZ
OFF
Do not put the router/device into DMZ unless there is a specific reason.
UPnP
OFF
This prevents devices from automatically requesting port mappings.
DDoS Protection
ON
Port Forwarding
If there are no rules, leave it alone.
Do not create port-forwarding rules unless you specifically need one.
ACL / Filtering / MAC / IP-MAC / Static ARP
If there are no rules configured, don’t create random rules just to make the router “more secure.”
Incorrect firewall rules can break normal network operation.


⸻


17. Remote Web Port
The X21 may show:
Remote Web Port: 443
with an explanation that local LAN access can still use port 80 while another port is used for remote access.
Do not assume that changing 443 disables remote access.
Changing the number generally changes the port; it does not necessarily disable the service.
Therefore, leave it at its existing value unless the actual WAN-management behavior has been established.


⸻


18. Wi-Fi configuration
A stable configuration used during testing was:
2.4 GHz
Mode: 11b
Bandwidth: 20 MHz
Channel: Auto
WMM: ON
Power: 100%
5 GHz
Mode: 11A/N/AC
Channel: 36
Bandwidth: 80 MHz
DFS: OFF
WMM: ON
Power: 100%
WPS:
OFF
Do not keep changing Wi-Fi settings if the Wi-Fi connection is already stable.


⸻


19. Improving 4G signal
Hidden firmware settings are not a magic signal booster.
The most important measurements are:
RSRP
RSRQ
SINR
For example, a connection showing approximately:
RSRP: -106 dBm
RSRQ: -11 dB
SINR: 0 dB
has a much bigger radio-quality problem than a Wi-Fi configuration problem.
Practical improvements
Try:
Place the router near a window.
Put it higher up if possible.
Keep it away from large metal objects.
Rotate/reposition it.
Wait for the cellular readings to update.
Compare RSRP/RSRQ/SINR at different locations.
A good physical location can produce a much larger improvement than changing obscure engineering settings.
An appropriate 4G MIMO external antenna, if compatible with the X21 and the local bands, can also be considered.


⸻


20. Do not blindly use these engineering functions
The X21 may expose powerful functions such as:
AT Commands
TCPDUMP
Network Tools
Remote Packet Capture
Firmware Update
Configuration Update
Telnet
ADB
Factory Restore
Having access to them does not mean they should be used.
In particular, don’t send random AT commands or erase system partitions.


⸻


21. Final recommended X21 setup
For a normal 4G SIM-router installation:
Network Mode → 4G Only
WAN Mode → Mobile Network Mode

SRS Antenna Rotation → ON
TX Space MIMO → ON

ADB → OFF
Telnet → OFF
WPS → OFF
UPnP → OFF
DMZ → OFF
DDoS Protection → ON

Port Forwarding → No unnecessary rules
ACL Firewall → No unnecessary rules

Automatic Firmware Update → OFF
Use a strong administrator password and keep the router firmware stable once everything is working.


⸻


22. Most important lesson
The X21 is not simply a normal Wi-Fi router with one “unlock” button.
The device contains several layers:
Web interface
↓
Engineering settings
↓
Router/TZ software
↓
Indoor-unit software
↓
Cellular modem
↓
Carrier/SIM/network configuration
Changing one layer does not necessarily unlock another.
The most useful discovery was that compatible X21/X21G firmware can expose additional engineering controls through:
Page.level=1
and, on compatible firmware, the hidden ADB Switch can provide ADB access to the underlying Linux system.
Once finished, disable ADB and Telnet again rather than leaving debugging access permanently enabled.


⸻


⚠️ Firmware warning
Before flashing any X21/X21G firmware:
Verify the exact hardware.
Verify the firmware filename.
Keep a recovery plan.
Do not mix unrelated X21/X21G packages.
Do not erase bootloader/partition information unless you have a confirmed recovery method.
A router is not exactly like a Windows PC. You cannot safely “format everything” and reinstall arbitrary software. The bootloader, partition layout, modem firmware and router firmware all matter.
The safest goal is to gain the required administrative access, configure the router properly, and then stop changing things once it is stable.
 
ZLT X21 / X21G — Unlock, Engineering Access, SIM Setup & Security Guide
This guide documents a practical method for gaining additional administrative/engineering access on the ZLT X21 / X21G and then configuring it for normal use with a SIM card.
Important: X21 and X21G firmware packages are hardware/model specific. Do not flash a firmware package just because it says X21. Verify that it is specifically for your X21G hardware. An incorrect firmware can brick the router.


⸻


1. What this procedure actually unlocks
There are several different meanings of “unlock” on the X21:
Web administrator access
Hidden/engineering settings
ADB access
Root shell access
Ability to inspect and modify system configuration
SIM/APN/network configuration
These are different from a guaranteed carrier/baseband unlock.
Therefore, don’t advertise this as a guaranteed method for removing every possible carrier restriction. It is more accurate to describe it as:
Unlocking additional administrative/engineering access and gaining root ADB access on supported X21/X21G firmware.


⸻


2. Before starting
You need:
ZLT X21/X21G
A Mac or Windows computer
USB/network access to the router
Router web interface
ADB platform-tools if you want root shell access
A firmware package specifically matching the X21G hardware
The router’s normal web address in this setup is:
You do not have permission to view the full content of this post. Log in or register now.
The exact menus can vary depending on firmware.


⸻


3. Firmware — the important part
One firmware package used during the investigation was:
X21G_1.10.23_usr_UN2020C_20211116_normal_update.swu
The important point is not simply the version number. The package must match the X21G hardware.
After flashing, the device may show something that looks confusing:
Software Version: 1.16.1.4
TZ Version: 1.10.23
This does not necessarily mean the firmware flash failed.
The X21 has multiple software components. The displayed “Software Version”, TZ version, indoor-unit firmware and modem firmware are not necessarily the same thing.
For example, an X21G can report:
Model: ZLT X21
Hardware: TZ7.823.407
TZ Version: 1.10.23
Indoor Unit firmware: X21G_V1.8.11
Modem: Orca/udx710 platform
Therefore, record all version fields before deciding that a firmware change worked or failed.


⸻


4. Exposing the hidden engineering menu
After logging into the router’s web interface:
Open the router web interface.
Open the browser developer tools.
Use the Console.
Enter:
Page.level=1
Press Enter.
On compatible firmware, this changes the web interface level and exposes additional engineering/system settings.
If it returns:
1
the command was accepted.
Refresh/open the router interface again if necessary.


⸻


5. Hidden System Settings
After Page.level=1, additional settings can appear under:
Management → System Settings
Depending on firmware, you may see items such as:
Change Password
Change Username
Time Settings
Restore Factory Settings
Import/Export Configuration
Telnet Switch
Module LOG switch
ADB Switch
SFP IPA Switch
COMMLOG Backup Setting
Abnormal Automatic Restart Switch
TR069 LOG Switch
YOCTO LOG Switch
The exact list varies between firmware versions.


⸻


6. Enable ADB
On firmware where the hidden ADB Switch is available:
Management → System Settings → ADB Switch
Enable ADB and save/apply the setting.
The router can then expose ADB on:
192.168.70.1:5555
Do not enable Telnet simply because it is available. ADB was sufficient for the root-shell work.


⸻


7. Connect from a Mac
Download Android platform-tools and place the folder somewhere convenient.
For example:
cd ~/Downloads/platform-tools
Check ADB:
./adb version
Then connect:
./adb connect 192.168.70.1:5555
If the connection succeeds:
./adb shell
On the successfully unlocked X21/X21G setup, this produced a root shell similar to:
root@udx710-module-pi:/ #
That means you have root-level shell access to the router’s underlying Linux environment.


⸻


8. Setting the web superadmin password
From the root ADB shell, the mdlcfg utility can be used on compatible firmware.
The relevant configuration commands are:
mdlcfg -f SYS_WEB_SUPER_PWD_RULE="1"
mdlcfg -a SYS_WEB_SUPER_PWD_RULE="1"

mdlcfg -f SYS_SUPER_LOGIN_PWD="<YOUR-OWN-PASSWORD>"
mdlcfg -a SYS_SUPER_LOGIN_PWD="<YOUR-OWN-PASSWORD>"

mdlcfg -c
Replace:
<YOUR-OWN-PASSWORD>
with a strong password of your choice.
Never post your actual password in a public forum.
After applying the configuration, the web interface can accept the superadmin account on firmware that supports this configuration.


⸻


9. A note about changing the username
Changing the visible administrator username and changing the underlying superadmin account are not necessarily the same thing.
On some X21 firmware, the web interface allows a username to be changed, but the underlying superadmin configuration may continue to use:
superadmin
Therefore, don’t assume a successful “Change Username” message means that every internal administrator account has been renamed.
The important thing is to establish a working administrator account and a strong password.


⸻


10. SIM / APN configuration
Once administrative access is available, configure the SIM through the normal network settings.
For a different carrier:
Insert the SIM.
Check SIM status.
Check network registration.
Select the appropriate network mode.
Configure the carrier’s APN.
Save/apply.
Reconnect the mobile data connection.
If the router shows a mobile IP but there is no Internet, check:
APN
default route/gateway
DNS
network registration
selected network mode
carrier compatibility
A registered SIM does not automatically mean that Internet routing is working.


⸻


11. Recommended 4G-only configuration
If the local area has poor or no useful 5G coverage, there is no reason to force 5G.
Under the network settings:
Network Mode → 4G Only
This avoids the router unnecessarily looking for 5G when the usable network is LTE.


⸻


12. WAN Mode
Under:
Network Settings → WAN Mode
Available choices can include:
Mobile Network Mode
Wired Network Mode
WiFi-2.4G Network Mode
WiFi-5G Network Mode
Mobile/Wired Network Mode
For a router being used with a SIM as the Internet connection:
WAN Mode → Mobile Network Mode


⸻


13. 4/5G Display Solution
Some X21 firmware has:
Internet Function → 4/5G Display Solution
The choices can be:
A
B
C
D
These settings determine how the interface labels/displays different LTE/NSA/NR states.
They do not directly increase cellular signal strength.
If the router is being used as a 4G-only device, changing this setting is generally unnecessary.


⸻


14. UE Capability Configuration
Under:
Internet Function → UE Configuration → UE Capability Config
The following options were found:
SRS Antenna Rotation → ON
TX Space MIMO Switch → ON
Recommended:
SRS Antenna Rotation → ON
TX Space MIMO → ON
These should normally be left enabled rather than disabling modem radio capabilities without a specific reason.
Under:
UE Configuration → Other Configuration
If the switch is already OFF, leave it OFF unless you know exactly what the option does.


⸻


15. Security configuration
After obtaining root/engineering access, do not leave debugging services enabled unnecessarily.
Recommended final state:
Setting
Recommended
ADB
OFF after finishing
Telnet
OFF
WPS
OFF
UPnP
OFF
DMZ
OFF
DDoS Protection
ON
Automatic Firmware Update
OFF if you want to control firmware changes
Port Forwarding
No unnecessary rules
ACL Firewall
No unnecessary rules
Remote Web Port
Leave at 443 unless there is a specific reason to change it
Strong admin password
YES
Important
Do not assume:
TR069 LOG Switch
YOCTO LOG Switch
are the same thing as the actual remote-management service.
They are logging-related settings. Don’t randomly disable them simply because their names contain TR069 or YOCTO.


⸻


16. Firewall settings
Useful safe defaults:
DMZ
OFF
Do not put the router/device into DMZ unless there is a specific reason.
UPnP
OFF
This prevents devices from automatically requesting port mappings.
DDoS Protection
ON
Port Forwarding
If there are no rules, leave it alone.
Do not create port-forwarding rules unless you specifically need one.
ACL / Filtering / MAC / IP-MAC / Static ARP
If there are no rules configured, don’t create random rules just to make the router “more secure.”
Incorrect firewall rules can break normal network operation.


⸻


17. Remote Web Port
The X21 may show:
Remote Web Port: 443
with an explanation that local LAN access can still use port 80 while another port is used for remote access.
Do not assume that changing 443 disables remote access.
Changing the number generally changes the port; it does not necessarily disable the service.
Therefore, leave it at its existing value unless the actual WAN-management behavior has been established.


⸻


18. Wi-Fi configuration
A stable configuration used during testing was:
2.4 GHz
Mode: 11b
Bandwidth: 20 MHz
Channel: Auto
WMM: ON
Power: 100%
5 GHz
Mode: 11A/N/AC
Channel: 36
Bandwidth: 80 MHz
DFS: OFF
WMM: ON
Power: 100%
WPS:
OFF
Do not keep changing Wi-Fi settings if the Wi-Fi connection is already stable.


⸻


19. Improving 4G signal
Hidden firmware settings are not a magic signal booster.
The most important measurements are:
RSRP
RSRQ
SINR
For example, a connection showing approximately:
RSRP: -106 dBm
RSRQ: -11 dB
SINR: 0 dB
has a much bigger radio-quality problem than a Wi-Fi configuration problem.
Practical improvements
Try:
Place the router near a window.
Put it higher up if possible.
Keep it away from large metal objects.
Rotate/reposition it.
Wait for the cellular readings to update.
Compare RSRP/RSRQ/SINR at different locations.
A good physical location can produce a much larger improvement than changing obscure engineering settings.
An appropriate 4G MIMO external antenna, if compatible with the X21 and the local bands, can also be considered.


⸻


20. Do not blindly use these engineering functions
The X21 may expose powerful functions such as:
AT Commands
TCPDUMP
Network Tools
Remote Packet Capture
Firmware Update
Configuration Update
Telnet
ADB
Factory Restore
Having access to them does not mean they should be used.
In particular, don’t send random AT commands or erase system partitions.


⸻


21. Final recommended X21 setup
For a normal 4G SIM-router installation:
Network Mode → 4G Only
WAN Mode → Mobile Network Mode

SRS Antenna Rotation → ON
TX Space MIMO → ON

ADB → OFF
Telnet → OFF
WPS → OFF
UPnP → OFF
DMZ → OFF
DDoS Protection → ON

Port Forwarding → No unnecessary rules
ACL Firewall → No unnecessary rules

Automatic Firmware Update → OFF
Use a strong administrator password and keep the router firmware stable once everything is working.


⸻


22. Most important lesson
The X21 is not simply a normal Wi-Fi router with one “unlock” button.
The device contains several layers:
Web interface
↓
Engineering settings
↓
Router/TZ software
↓
Indoor-unit software
↓
Cellular modem
↓
Carrier/SIM/network configuration
Changing one layer does not necessarily unlock another.
The most useful discovery was that compatible X21/X21G firmware can expose additional engineering controls through:
Page.level=1
and, on compatible firmware, the hidden ADB Switch can provide ADB access to the underlying Linux system.
Once finished, disable ADB and Telnet again rather than leaving debugging access permanently enabled.


⸻


⚠️ Firmware warning
Before flashing any X21/X21G firmware:
Verify the exact hardware.
Verify the firmware filename.
Keep a recovery plan.
Do not mix unrelated X21/X21G packages.
Do not erase bootloader/partition information unless you have a confirmed recovery method.
A router is not exactly like a Windows PC. You cannot safely “format everything” and reinstall arbitrary software. The bootloader, partition layout, modem firmware and router firmware all matter.
The safest goal is to gain the required administrative access, configure the router properly, and then stop changing things once it is stable.
 

About this Thread

  • 32
    Replies
  • 9K
    Views
  • 21
    Participants
Last reply from:
Shehan Bandara

Trending Topics

Online now

Members online
394
Guests online
3,811
Total visitors
4,205

Forum statistics

Threads
2,338,262
Posts
29,303,048
Members
1,126,158
Latest member
nksoraa1
Back
Top