How-To
How to Fingerprint Robot Vacuum Revisions for Valetudo
Step-by-step hardware guide to identifying secure-boot floors and motherboard revisions on Dreame and Roborock vacuums before flashing.
Valetudo compatible vacuums are not a brand list—they are 49 documented SKUs on the maintainer’s Supported Robots page as of 21 August 2026, each with revision fingerprints you must match before flash. Dreame and Roborock ship silent motherboard changes—different NAND vendors, secure boot chains, or SoC twins—under identical retail names. Fingerprint Wi-Fi SSID, serial prefix, firmware build, and manufacturing era first; connect the UART breakout or open the tray only after those signals pass upstream gates.
Quick answer: How do you fingerprint robot vacuum revisions for Valetudo?
(1) Confirm exact model on valetudo.cloud Supported Robots. (2) Capture fingerprints: Wi-Fi AP during setup, serial prefix on label, button count, About-screen FW build, manufacturing date. (3) On Dreame aarch64, update vendor FW past secure-boot floors before UART. (4) On Roborock Q7 Max, treat 2024+ factory stock as SkyHigh NAND lottery. (5) Flash only when fingerprints match a documented rootable row—skip purchase if they match a locked twin.
Source: Valetudo Supported Robots
Why revision fingerprinting beats brand shopping
Shoppers searching valetudo compatible vacuums often stop at “Dreame roots” or “Roborock local API.” Vendors ship motherboard revisions that never change the box art: Dreame swaps R2394 L20 Ultra PCBs for locked R2253 twins; Roborock substitutes SkyHigh NAND on Q7 Max units built after roughly Q2 2024 while YouTube titles still describe a 2022 workflow1. Xiaomi 1C vacuums broadcast different dreame.vacuum.* SSIDs that map to incompatible exploit families under the same badge.
For privacy-focused buyers, the failure mode is not a bad download mirror—it is maps you cannot keep local, telemetry you cannot firewall, and warranty seals broken on hardware upstream marks not rootable. Bottom line: treat compatibility as a per-revision claim verified against install pages, not a per-brand promise.
Methodology: how we built the fingerprint registry
On 21 August 2026, we re-read every model block on Supported Robots and extracted pre-flash fingerprints upstream documents: Wi-Fi AP strings, serial prefixes, button counts, manufacturing cutoffs, minimum firmware builds, and post-disassembly traps (NAND vendor)1. UART pad notes were cross-checked against Dennis Giese’s hardware corpus on robotinfo.dev where service-port photos matter, but lock vs root decisions follow maintainer install prose only2.
Where I’m less sure — reseller listings rarely show NAND silkscreen or UART header pitch; Q7 Max rootability can stay unknown until the tray opens1. Anecdotally, buyers who skip a $5 seller serial photo lose more time than the Hypfer breakout PCB costs.
Original research: Dreame and Roborock fingerprint signal matrix
This citable dataset is the page’s original research: observable signals that separate rootable from locked hardware under unchanged marketing names. Rows were verified line-by-line on 21 August 20261.
| Marketing name | Fingerprint signal | Rootable value | Locked / risky twin | Observable before purchase? |
|---|---|---|---|---|
| Dreame L20 Ultra | Serial prefix | R2394 | R2253 — NOT rootable | Yes — label / seller photo |
| Xiaomi 1C | Wi-Fi AP during setup | dreame.vacuum.mc1808 | Other dreame.vacuum.* SSIDs | Yes — factory setup Wi-Fi list |
| Dreame D9 | Top-panel buttons | 3 buttons | D9 Max — different robot | Yes — photos or in-store check |
| Dreame L10s Ultra | Feature set | Original L10s Ultra (AI cam, no extendable mop) | L10s Ultra Gen2 | Partial — label + feature check |
| Dreame L10 Pro | About-screen FW | Vendor FW ≥ 1138 | Below floor → U-Boot reject | After temporary vendor FW update |
| Dreame Z10 Pro | About-screen FW | Vendor FW ≥ 1156 | Stale FW on new-old stock | After temporary vendor FW update |
| Xiaomi Vacuum-Mop 2 Ultra | About-screen FW | Vendor FW ≥ 1167 | UART connects but flash fails | After temporary vendor FW update |
| Roborock S5 | Firmware build | FW ≥ 2008 for segment maps | Older FW lacks segment support | Yes — About screen if powered |
| Xiaomi V1 (Roborock-made) | Manufacturing date | Before 2020-03 | Post-cutoff → Vinda disassembly | Yes — label date code |
| Roborock Q7 Max / Q7 Max+ | NAND vendor | Pre-Q2 2024 used stock (anecdotal) | SkyHigh NAND ~2024+ factory | No — usually post-teardown |
Stat snapshot: In our August 2026 audit, 10 of 49 supported SKUs carry at least one documented twin, floor, or post-open trap—and Q7 Max is the only row where upstream cannot fingerprint NAND from the label alone1.
The full 49-model database with install deep-links lives in our supported vacuums list. This page teaches how to read the fingerprint columns before you download firmware.
Dreame secure-boot floors and UART revision checks
Most 2024–2026 Dreame flagships use aarch64 builds where U-Boot verifies the vendor kernel before any UART install script can persist Valetudo. Upstream lists minimum vendor firmware builds—not suggestions:
| Model | Architecture | Secure boot | Minimum vendor FW (upstream) | Symptom if below floor |
|---|---|---|---|---|
| Dreame L10 Pro | aarch64 | yes | since FW 1138 | Exploit chain stale; boot rejects payload |
| Dreame Z10 Pro | aarch64 | yes | since FW 1156 | Root fails at bootloader gate |
| Xiaomi Vacuum-Mop 2 Ultra | aarch64 | yes | since FW 1167 | UART connects but flash does not stick |
| Dreame D9 / F9 / MOVA Z500 | armv7 / lowmem | no | — | UART at 115200 or 500000 baud |
Procedure: Join the robot to Wi-Fi temporarily, let it pull current vendor firmware, confirm the build on the About screen, then run the offline UART install from a Linux laptop on UPS power13. Skipping the update leaves you on a build that looks like the right name but dies at secure boot—classic silent revision behavior when warehouses sell old FW on new PCB spins.
Dreame UART fingerprint checklist (pre-adapter)
| Step | Action | Pass example | Fail example |
|---|---|---|---|
| 1 | Match model on Supported Robots | Dreame L10s Ultra listed | L10s Ultra Gen2 absent |
| 2 | Read setup Wi-Fi AP | dreame.vacuum.mc1808 on 1C | Other dreame.vacuum.* on 1C |
| 3 | Photograph serial label | L20 Ultra R2394 | L20 Ultra R2253 |
| 4 | Count physical buttons | D9 3-button top panel | D9 Max layout |
| 5 | Record FW build after vendor update | L10 Pro ≥ 1138 | L10 Pro 1120 |
Roborock motherboard revisions: OTA era vs NAND traps
Roborock splits across three bootloader eras relevant to fingerprinting:
| Era | Models | Fingerprint signals | Silent revision risk |
|---|---|---|---|
| OTA laptop | S5; V1 pre-2020-03 | FW build, mfg date on label | V1 post-2020-03 needs disassembly |
| FEL disassembly | S6–S7 family, Q7 Max | Tray open + signed tooling | Vinda vs init override on early S6 |
| Storage lock | Q7 Max ~2024+ factory | Same FEL path | SkyHigh NAND — root fails after open1 |
Upstream’s September 2024 Q7 Max update is explicit: the procedure is safe (no brick) but may not work on SkyHigh storage—and you learn that after disassembly1. That is a silent PCB/storage revision, not a bad forum mirror.
”You’ll only find out that it’s SkyHigh NAND once you’ve disassembled the robot and thus can’t return it to the seller anymore.”
For shoppers who need seals intact, cross-shop to Dreame UART models or legacy Roborock S5 OTA paths documented in our flash walkthrough.
Step-by-step fingerprint workflow (before any flash)
Use this sequence before writing any Valetudo image. It keeps flashes offline except for the optional Dreame vendor FW update step secure boot requires.
Phase 1 — Canonical list gate
- Open Supported Robots and find your exact model string.
- If absent, stop—use requests.valetudo.cloud instead of forum exploit chains.
- Note the root interface column: OTA, UART, or disassembly (matrix reference).
Phase 2 — Capture fingerprints (no tools required)
| Signal | Where to read it | Tools needed |
|---|---|---|
| Wi-Fi AP during setup | Phone Wi-Fi list | None |
| Serial prefix | Underside label / seller photo | None |
| Button count | Physical controls | None |
| Firmware build | About screen (temporary vendor FW) | Vendor app briefly |
| Manufacturing era | Label date / seller disclosure | None |
Phase 3 — Compare against locked twins
If any signal matches a locked twin row in the dataset table above, do not purchase (or plan to resell to a cloud-only buyer). Hard locks—R2253, wrong 1C SSID, L10s Ultra Gen2—have no documented workaround as of August 20261.
Phase 4 — Flash only after gates pass
| Path | When fingerprints pass | Offline rule |
|---|---|---|
| Dreame UART | SSID/serial/FW floor OK | Hypfer breakout PCB + install script from UPS laptop |
| Roborock S5 OTA | FW ≥ 2008, correct era | Linux live USB exploit—seals intact |
| Roborock FEL | Accept Q7 Max NAND lottery | Tray open—never power-cycle mid-write |
Download armv7, armv7-lowmem, or aarch64 artifacts from official releases only—wrong architecture will not boot4.
Named buyer scenarios
Nadia, Denver — marketplace Dreame L20 Ultra at $420 with no serial photos. She asks the seller for a label shot; prefix is R2253. Upstream marks it not rootable; no offline flash path exists as of August 20261. Verdict: pass on the listing—UART hours will not convert the twin.
Oliver, Hamburg — used Roborock S5 (FW 2014) for €130 from a refurb shop. He fingerprints OTA eligibility, runs the laptop exploit on Ubuntu live USB, flashes armv7 Valetudo, and maps MQTT to Home Assistant on VLAN 40. Verdict: lowest-friction Roborock privacy path when you accept older navigation.
Jasmine, Phoenix — new Q7 Max+ from a big-box retailer, May 2025 build. She assumes 2022 forum posts apply. After FEL disassembly she hits SkyHigh NAND; upstream documents failure with no software workaround1. Verdict: treat 2024+ factory Q7 Max as a gamble; fingerprinting could not save her because NAND is invisible pre-open.
Steel-man: “Supported list is enough—skip the fingerprint ritual”
Best case against fingerprinting: The official Supported Robots list is exhaustive—if the name matches, the maintainer already validated the exploit chain. Buying new from a major retailer with 30-day returns beats obsessing over serial prefixes. For Roborock local API users, stock local network mode on recent S7/S8 lines avoids rooting entirely while keeping warranty intact.
Rebuttal: The list is exhaustive at the model-string level, not the silent twin level. L20 Ultra, 1C, and Q7 Max are counterexamples where upstream documents different hardware under the same marketing name1. Returns expire faster than UART adapters ship; secure-boot floors punish “new old stock” with stale FW. For a privacy-first threat model—MQTT on an IoT VLAN, maps that never phone Shenzhen—buying the wrong revision costs weeks, not minutes. Fingerprint first; flash second.
After fingerprints pass: LAN hardening
Fingerprinting gets you to the right hardware row; data custody still depends on network design after flash.
- Complete the flash walkthrough for your root interface row.
- Enable MQTT with username/password; integrate via the Home Assistant install guide.
- Move the vacuum to an IoT VLAN that denies WAN except NTP.
- Export Valetudo settings after first successful boot—recovery beats re-rooting.
- Delete vendor cloud accounts only after you confirm local control works.
Checklist
- Confirm exact model on valetudo.cloud Supported Robots (21 August 2026 snapshot).
- Capture fingerprints: SSID, serial prefix, buttons, FW build, mfg date—before UART or tray surgery.
- Compare signals against locked-twin rows; abort purchase if any match a documented hard lock.
- For Dreame aarch64: update vendor FW past secure-boot floor before Hypfer breakout PCB install.
- For Roborock Q7 Max: treat 2024+ factory stock as SkyHigh NAND lottery.
- Download correct armv7 / armv7-lowmem / aarch64 Valetudo build from official releases.
- Flash from UPS-backed Linux laptop—never interrupt power mid-write.
- Post-flash: MQTT auth, IoT VLAN deny-WAN, export settings before deleting vendor apps.
Verdict
For privacy-conscious buyers in August 2026, valetudo compatible vacuums are defined by revision fingerprints, not shelf placement. Dreame UART paths reward shoppers who verify SSID strings, serial prefixes, and secure-boot firmware floors before the breakout PCB touches the service port. Roborock S5 OTA remains the lowest-mechanical-risk route on legacy hardware. Roborock Q7 Max is for owners who accept post-disassembly NAND discovery—not a casual pre-purchase fingerprint.
Use this guide to fingerprint hardware before flash; use the silent PCB revision deep-dive for bootloader theory; use the Roborock & Dreame matrix to classify your root path. When fingerprints pass, continue to offline flash steps.
Primary sources
| ID | Source | URL |
|---|---|---|
| 1 | Supported Robots (canonical list + per-model rooting) | valetudo.cloud/pages/general/supported-robots/ |
| 2 | Dennis Giese — vacuum hardware overview | robotinfo.dev |
| 3 | Hypfer Dreame UART breakout PCB | github.com/Hypfer/valetudo-dreameadapter |
| 4 | Valetudo official releases | github.com/Hypfer/Valetudo/releases |
| 5 | Buying supported robots | valetudo.cloud/pages/general/buying-supported-robots/ |
Frequently Asked Questions
How do I know if my vacuum is Valetudo compatible before buying?
Confirm the exact model on valetudo.cloud Supported Robots, then fingerprint hardware revisions: Wi-Fi AP name during setup, serial prefix on the label, button count, and manufacturing date. Dreame aarch64 models also need vendor firmware past secure-boot floors (e.g., L10 Pro since FW 1138). Roborock Q7 Max 2024+ factory stock may use SkyHigh NAND that blocks root only after disassembly.
What Wi-Fi SSID indicates a rootable Xiaomi 1C for Valetudo?
Only the dreame.vacuum.mc1808 AP string maps to the supported 1C hardware revision upstream documents as of August 2026. Other dreame.vacuum.* SSIDs under the same “1C” marketing name are incompatible SoCs—not patchable with a different flash image.
Which Dreame L20 Ultra serial prefix is Valetudo compatible?
Serial numbers starting with R2394 are the rootable L20 Ultra revision upstream documents. Serial R2253 is a visually identical twin marked NOT rootable with no documented workaround as of August 2026. Request a seller photo of the underside label before checkout.
Can I fingerprint Roborock Q7 Max NAND without opening the case?
Usually not. Upstream’s September 2024 note states SkyHigh-brand NAND on Q2 2024+ factory units blocks the documented FEL root path—and you confirm storage vendor only after tray disassembly, often past return windows. Treat new Q7 Max as a gamble unless you buy used pre-2024 stock with disclosed manufacturing dates.
What secure-boot firmware floors matter on Dreame before UART root?
Examples upstream lists as of August 2026: Dreame L10 Pro aarch64 since FW 1138, Z10 Pro since FW 1156, Xiaomi Vacuum-Mop 2 Ultra since FW 1167. Below-floor vendor builds reject exploit payloads at U-Boot even when UART connects cleanly.
Do I need the Hypfer Dreame breakout PCB to fingerprint revisions?
No. Fingerprinting uses observable signals—SSID, serial, buttons, About-screen firmware strings—before any UART adapter touches the service port. The breakout PCB is required only after fingerprints pass and you run the install script from a UPS-backed Linux laptop.
Dataset (JSON-LD)
Footnotes
-
Valetudo Supported Robots, accessed 21 August 2026. https://valetudo.cloud/pages/general/supported-robots/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13
-
Dennis Giese — Vacuum Robot Overview. https://robotinfo.dev/ ↩
-
Hypfer valetudo-dreameadapter (UART breakout PCB). https://github.com/Hypfer/valetudo-dreameadapter ↩
-
Hypfer/Valetudo releases. https://github.com/Hypfer/Valetudo/releases ↩