Firmware & recoveryReviewed
Recover a Bricked TBox Ultra With QFIL (EDL, Firehose, UFS)
TBox Ultra won't boot? Flash Carlinkit's official recovery package with QFIL in EDL mode: Flat build, SM6350 firehose, UFS. Plus fixes for Sahara errors.
Carlinkit TBox UltraCarlinkit TBox Ultra 2Carlinkit TBox Ultra 3Carlinkit TBox Ultra 4Carlinkit TBox PlusCarlinkit TBox AmbientCarlinkit TBox UHDQuick answer
Hold the EDL button while plugging the Ultra into a Windows PC, then flash Carlinkit's complete recovery package with QFIL: Flat build, the SM6350 firehose programmer from that package, storage type UFS, and the rawprogram and patch XML files the package names. Five owners revived Ultra 1, 2, 3 and 4 units this way. A Sahara error almost always means the box is not in EDL mode or the programmer or package does not match it.
Before you start
- A Windows 10 or 11 PC with a free USB port and administrator rights
- The official recovery package for your exact Ultra model, from Carlinkit support
- The Qualcomm USB driver and the QPST package (QFIL ships inside it)
- The USB-C data cable that came with the box, or another known-good data cable
- A paper clip or pin if your Ultra has a pinhole button
Time: about 60 minutes. Tools: Windows PC, QPST / QFIL, Qualcomm USB driver, USB-C data cable, paper clip.
Applies to
- Devices
- Connection to the car
- CarPlay and Android Auto
- Firmware in confirmed reports
- Carlinkit TBox Ultra: 2026-03-20; Carlinkit TBox Ultra 3: 2026-03-20; Carlinkit TBox Ultra 4: 2025-10-21
- Highest risk on this page
- Brick risk
Is your Ultra really bricked?
A bricked box never finishes booting: the LED lights and stays that way, the head unit never shows the box, and a phone app that lists USB devices does not see it either. Before you reach for QFIL, rule out the three faults that look like a brick but are not.
- Wrong protocol. The button you use for EDL also switches CarPlay and Android Auto when pressed briefly on a running box. Owners who pressed it “to reset” ended up in a protocol their car does not support. Switch back as described in switch the box’s protocol.
- ADB mode left on. After engineering code 142618 the USB port talks to computers, not cars. See “Device not supported” after enabling ADB.
- Black screen on a running box. If the box boots (Wi-Fi and Bluetooth appear) but the screen stays dark, read black screen after boot on TBox Ultra first.
If the box boots far enough for the FOTA app, a normal local firmware update is safer than anything on this page. QFIL is for the case where nothing else can reach the box.
What QFIL and EDL do
Every Ultra uses a Qualcomm SM6350 (QCM6350) chip. Below Android there is a read-only boot ROM with an emergency download mode, called EDL. In EDL the box shows up on a PC as “Qualcomm HS-USB QDLoader 9008”, even when everything above it is broken.
QFIL is Qualcomm’s flashing tool. It first sends a small loader, the firehose programmer, over a protocol called Sahara. The programmer then writes the partition images to the box’s UFS storage, following the XML files in the recovery package: rawprogram files say which image goes where, patch files fix up the partition table.
That is why the package has to match the box exactly. A programmer for another chip fails at the Sahara stage; images for another model can write successfully and still leave a box that does not start.
Get the right recovery package
Carlinkit makes recovery packages per model and chipset. Owners described the Ultra packages as Android 15 UFS image sets; the ones discussed carried the 21 Oct 2025 and 20 Mar 2026 builds, and the date you receive may differ. The Ultra 3 has its own firmware line: one Ultra 3 owner who installed a build made for the Ultra 2 found the box sluggish and the small display on its case showing interference, and other owners advised using only Ultra 3 builds on an Ultra 3 to keep that display working.
Unzip the package to a short path with no spaces or non-Latin characters, for example C:\recovery\ultra. Inside you should find:
- a firehose programmer, a file named like
prog_firehose_ddr.elf; - one or more
rawprogram*.xmlfiles and matchingpatch*.xmlfiles; - the partition images themselves (
.img,.elf,.mbn,.bin); - often a text or picture note saying which
rawprogramfile to use.
A normal update.zip for the FOTA app is not a recovery package. QFIL cannot use it.
Steps
Prepare a Windows PC for QFIL
- Brick risk
- Time: 20 minutes
- Worked for 2 of 3 reports
Warranty warning: this changes system partitions. A wrong file or an interrupted step can leave the box unbootable, and manufacturers treat it as outside warranty. Back up first and keep the undo steps open.
- Install the Qualcomm USB driver.
- Install the QPST package and start QFIL from Start → QPST → QFIL, not from a loose copy found elsewhere.
- Sign in to Windows with an administrator account whose user name uses only Latin letters and has no spaces. Create a new local account if yours does not.
- Pause third-party antivirus for the session if it quarantines QFIL files.
- Keep the recovery files in the short path you chose above.
Both PC fixes here came from real failures. One owner saw two Sahara errors in a row from a stand-alone QFIL; the copy that ships inside QPST worked straight away. On Windows 11, another owner’s QFIL hung and its partition menu would not open until he made a clean administrator profile with a plain English name, because QFIL writes its temporary files under that profile. A third owner ran Windows 11 without any of this, so treat the profile step as the fix for that symptom, not a rule.
Put the Ultra into EDL mode
- Brick risk
- Time: 5 minutes
- Recommended in the community FAQ
Warranty warning: this changes system partitions. A wrong file or an interrupted step can leave the box unbootable, and manufacturers treat it as outside warranty. Back up first and keep the undo steps open.
- Unplug the box from the car, charger and PC.
- Find the EDL button. On the Ultra 1 it sits in the pinhole on the side, next to the protocol LED. On the Ultra 2 and Ultra 3 it is a button on the underside of the case.
- Press and hold the button.
- Still holding it, connect the box to the PC with the data cable.
- Release the button after a second or two.
- Open Device Manager. Under Ports (COM & LPT) you should see Qualcomm HS-USB QDLoader 9008 (COMx). Note the COM number.
If no 9008 port appears, unplug and repeat; holding the button before the cable goes in is the part owners most often missed. A short press on a running box only switches the protocol and does not enter EDL.
Set up QFIL and check that it can read the box
- Brick risk
- Time: 10 minutes
- Recommended in the community FAQ
Warranty warning: this changes system partitions. A wrong file or an interrupted step can leave the box unbootable, and manufacturers treat it as outside warranty. Back up first and keep the undo steps open.
- In QFIL, click Select Port and choose the 9008 port.
- Under Select Build Type, choose Flat Build.
- Under Select Programmer, browse to the firehose
.elffile inside the recovery package. - Open Configuration → FireHose Configuration and set Device Type to UFS. Leave the other options at their defaults. Make sure Erase All Before Download is not ticked.
- Open Tools → Partition Manager. A table of partitions should appear.
- Close the partition table without changing anything.
If the partition table opens, QFIL, the drivers, the programmer and the storage type are all correct, and the real flash has every chance of starting. Run this check every time. Afterwards, unplug, reopen QFIL and re-enter EDL before flashing, so that the download starts from a fresh Sahara session.
Flash the official recovery package
- Brick risk
- Time: 15–25 minutes
- Worked for 5 of 5 reports
- Recommended in the community FAQ
Warranty warning: this changes system partitions. A wrong file or an interrupted step can leave the box unbootable, and manufacturers treat it as outside warranty. Back up first and keep the undo steps open.
- Re-enter EDL mode, reopen QFIL and select the 9008 port, programmer and UFS again.
- Click Load XML. Pick the
rawprogramfile your package names. For the Ultra 1, 2 and 3 packages owners usedrawprogram0_update_sd.xml. - When QFIL asks for the patch file, pick the matching
patchXML from the same folder. - Click Download and do not touch the PC, cable or box.
- Wait for Download Succeed in the log at the bottom of QFIL.
- Unplug the box, wait ten seconds, and connect it to a charger or the car.
- The first boot after recovery is slow. Give it several minutes.
Select Build Type : Flat Build
Select Programmer : C:\recovery\ultra\prog_firehose_ddr.elf
Device Type : ufs
Load XML : rawprogram0_update_sd.xml + patch0.xmlOwners revived an Ultra 1, 2, 3 and 4 this way. An Ultra 4 owner who had only the programmer got a Sahara protocol error; with the full recovery set his box worked again. An Ultra owner who had bricked his box by experimenting with build.prop values restored it with the 21 Oct 2025 recovery image. An Ultra 3 owner’s recovery left the 20 Mar 2026 build installed with the SIM working, and an Ultra 1 owner restored the same build and reported it ran stably.
The choice of rawprogram file matters for the SIM. The admins’ notes for the Ultra 1 and 2 packages warn that the wrong one leaves the SIM unusable, because some variants overwrite the modem area that holds the box’s IMEI.
Verify it worked
The box should boot to the stock launcher with a fresh setup. Then check:
- Settings → About shows a build date close to the package date.
- The head unit shows the box in your usual protocol. If not, switch protocol before suspecting the flash.
- Insert the SIM and open a web page with Wi-Fi off. If the SIM is not detected, or About → Status shows no IMEI, the wrong
rawprogramfile was used; see troubleshooting below. - Look at the status bar. One Ultra 4 owner got the network exclamation mark after recovery; the exclamation mark fix covers it.
One owner of another TBox model saw a “Device not activated” QR screen after recovery. Giving the box internet, by SIM or phone hotspot, cleared it; see QR code / device not activated.
Undo / rollback
There is no way back to the exact state before the brick, because a recovery flash wipes everything. Your realistic options afterwards:
- Move to any official build for your model with the FOTA local update; Carlinkit builds for the same model install over each other.
- If you had root or multitouch before, set it up again from root with Magisk or enable multitouch. Both start from a clean, booting box.
- If the box will not come back after two careful attempts with the correct package, it is a support case, not a QFIL case.
Troubleshooting this guide
“Sahara protocol error”, or “Unable to read packet header. Only read 0 bytes”. Check these in order:
- The box is not in EDL mode. Device Manager must show the 9008 port, not an Android or unknown device.
- The programmer does not match. The Ultra needs the SM6350 programmer from its own recovery package.
- The package does not match the chip or memory type. An Ambient owner had Sahara errors until he used the package for his chip in the right UFS or eMMC variant; then it worked.
- The QFIL build is the problem. Use the QFIL inside QPST, as above.
QFIL freezes or Partition Manager never opens on Windows 11. Use an administrator account with a Latin-only user name and no spaces, and keep the files in a short path.
“Failed to initialize (open whole lun) UFS”. The storage type in FireHose Configuration does not match the box. Every Ultra package owners described was UFS; on older TBox models this error meant eMMC was needed.
The SIM or IMEI is gone after recovery. This happened to an Ambient owner who ticked Erase All Before Download, and the admins warn that the wrong rawprogram variant in the Ultra 1 and 2 packages leaves the SIM unusable too. It wipes the partitions that hold your IMEI and radio calibration, and they are not in the recovery package. Contact Carlinkit support; do not install another box’s modem files.
The box stopped showing any sign of life after flashing single partitions. One Ultra owner wrote partitions one by one, filled the Bluetooth partition with zeros by mistake and lost the LED, ADB and video, although EDL still worked. Flash the whole package through its rawprogram and patch files only.
Download Succeed, but the box still does not boot. Flash again from a fresh EDL session. Then check you used the Ultra 3 package on an Ultra 3 and the Ultra 1/2 package on those models.
The PC never shows a 9008 port. Try a USB 2.0 port and another data cable, reinstall the Qualcomm driver, and hold the button before plugging in.
Other TBox models. The tool and steps are the same, but the programmer, memory type and XML order differ. Some older TBox Plus EM 668 units needed six separate passes, rawprogram0 with patch0 up to rawprogram5 with patch5, re-entering EDL between each. Follow the instructions inside your model’s package, and use which TBox do I have to be sure of the model first.
Related fixes
- Update TBox Firmware Locally With FOTA and a microSD CardAdvanced
- Root a Carlinkit TBox With Magisk via QFILBrick risk
- Enable ADB on an AI Box: USB, Wi-Fi and Ottocast Port 65535Advanced
- Enable Multitouch Pinch-Zoom on TBox Ultra, Plus and AmbientBrick risk
- QR Code or "Device Not Activated" After a TBox UpdateSafe
Did this work for you?
Tell us which fix worked (or didn't), with your box, firmware date and car. Reports are how fixes get confirmed and re-ranked.
Send a reportChangelog
- Last reviewed against new community reports:
- Confirmed by 8 community reports on Carlinkit TBox Ultra, Carlinkit TBox Ultra 2, Carlinkit TBox Ultra 3, Carlinkit TBox Ultra 4, Carlinkit TBox Ambient.
- Page updated:
"Confirmed" means a community member reported that the fix worked on their unit. We have not tested it on our own hardware. How we verify.