hi,
the V3b is a hauwei unit based on bcm6361.
we've got a root prompt on the V3B, but it's rumored that any change to the rootfs (read only jffs2) renders the unit non boot. I've not tried myself as there's no serial or jtag on the unit.
Has anyone any info on 'modern' CFEs, and if they do check the rootfs in some way, and if this can be disabled, or if the CFE can be replaced? Looks like access to the CFE flash area would be only via a specific broadcom driver - i.e. it's not part of the exposed mtd regions.