A Python script that enables root access on the T-Mobile (Wingtech) TMOHS1 (MDM9207) and replaces the stock firmware interface.
This is a fork of the original TMOHS1-Root-Utility. It expands on the original exploit by stripping the default carrier UI, replacing it with a custom web panel, and integrating local network management tools. Major major credit to them.
- Custom Web Panel: Replaces the stock T-Mobile web interface.
- Web Shell: Integrated root shell accessible directly through the web panel.
dnsmasqSupport: Manage custom DNS and DHCP directly from the interface.- Root Password Patch: Fixed the upstream bug to allow persistent root password updates.
- Root shell via telnet
- Temporarily or persistently enable ADB
- Disable OMA-DM update bootstrap
- On-device root FTP server to browse the filesystem
- Mood lighting control
- Mask hotspot data as "on-client-device" data (TTL modification)
- SIM unlock :(
- SSH server installation
- Other USB modes (can be implemented by editing
utils.py)
Requires Python >= 3.6 and pip.
pip install -r requirements.txt
Connect to the hotspot via USB tethering (recommended) or WiFi, then run:
python ./rootScript.py
For verbose output:
python ./rootScript.py -v
- Tested on Windows 10 & 11
- Assumes the hotspot IP is
192.168.0.1. - Security: The script leaves an unauthenticated root FTP server running on the device only if you enable it. Close it when finished by running
killall tcpsvdas root, or reboot the device. - You can build custom binaries and a portable cross-SDK using this custom Buildroot fork. Note: This is experimental.