!attention!
method requiring physical access to cmu with high risk, provided without detailed command, just steps.

The problem is that we need to make a memory dump of the spi flash drive.

  1. dump spi flash chip content (use ch340a and flashrom, or something like that)
  2. extract the squashfs image from it (located at address 0x070000),
  3. unpack squashfs,
  4. replace the password in passwd file
  5. pack everything back to squashfs image.
  6. insert squashfs image back on same offset 0x070000 of dump.
  7. flash modified dump back into cmu and freely use the serial console with the password we set.
  8. profit.