
The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more

Nexmon is our C-based firmware patching framework for Broadcom/Cypress WiFi chips that enables you to write your own firmware patches, for example, to enable monitor mode with radiotap headers and frame injection.
Below, you find an overview what is possible with nexmon. This repository mainly focuses on enabling monitor mode and frame injection on many chips. If you want additional features, the following projects might be interesting for you:
Our software may damage your hardware and may void your hardware’s warranty! You use our tools at your own risk and responsibility! If you don't like these terms, don't use nexmon!
The following devices are currently supported by our nexmon firmware patch.
| WiFi Chip | Firmware Version | Used in | Operating System | M | RT | I | FP | UC | CT |
|---|---|---|---|---|---|---|---|---|---|
| bcm4330 | 5_90_100_41_sta | Samsung Galaxy S2 | Cyanogenmod 13.0 | X | X | X | X | O | |
| bcm4335b0 | 6.30.171.1_sta | Samsung Galaxy S4 | LineageOS 14.1 | X | X | X | X | O | |
| bcm4339 | 6_37_34_43 | Nexus 5 | Android 6 Stock | X | X | X | X | X | O |
| bcm43430a11 | 7_45_41_26 | Raspberry Pi 3 and Zero W | Raspbian 8 | X | X | X | X | X | O |
| bcm43430a11 | 7_45_41_46 | Raspberry Pi 3 and Zero W | Raspbian Stretch | X | X | X | X | X | O |
| bcm43439a07 | 7_95_49 (2271bb6 CY) | Raspberry Pi Pico W | Pico SDK | X | X | X | X | ||
| bcm43451b1 | 7_63_43_0 | iPhone 6 | iOS 10.1.1 (14B100) | X | X | ||||
| bcm43455 | 7_45_77_0_hw | Huawei P9 | Android 7 Stock | X | X | X | X | X | |
| bcm43455 | 7_120_5_1_sta_C0 | Galaxy J7 2017 | ? | X | X | ||||
| bcm43455 | 7_45_77_0_hw(8-2017) | Huawei P9 | Android 7 Stock | X | X | X | X | X | |
| bcm434555 | 7_46_77_11_hw | Huawei P9 | Android 8 China Stock | X | X | X | X | X | |
| bcm43455 | 7_45_59_16 | Sony Xperia Z5 Compact | LineageOS 14.1 | X | X | X | X | X | |
| bcm43455c0 | 7_45_154 | Raspberry Pi B3+/B4 | Raspbian Kernel 4.9/14/19 | X | X | X | X | ||
| bcm43455c0 | 7_45_189 | Raspberry Pi B3+/B4 | Raspbian Kernel 4.14/19, 5.4 | X | X | X | X | ||
| bcm43455c0 | 7_45_206 | Raspberry Pi B3+/B4 | Raspberry Pi OS Kernel 5.4 | X | X | X | X | X | |
| bcm43455c0 | 7_45_234 (4ca95bb CY) | Raspberry Pi B3+/B4/5 | Raspberry Pi OS | X | X | ||||
| bcm43436b03 | 9_88_4_65 | Raspberry Pi Zero 2 W | Raspberry Pi OS Kernel 5.10 | X | X | X | X | X | |
| bcm4356 | 7_35_101_5_sta | Nexus 6 | Android 7.1.2 | X | X | X | X | O | |
| bcm4358 | 7_112_200_17_sta | Nexus 6P | Android 7 Stock | X | X | X | X | O | |
| bcm4358 | 7_112_201_3_sta | Nexus 6P | Android 7.1.2 Stock | X | X | X | X | O | |
| bcm43582 | 7_112_300_14_sta | Nexus 6P | Android 8.0.0 Stock | X | X | X | X | X | O |
| bcm43596a03 | 9_75_155_45_sta_c0 | Samsung Galaxy S7 | Android 7 Stock | X | O | X | |||
| bcm43596a03,2 | 9_96_4_sta_c0 | Samsung Galaxy S7 | LineageOS 14.1 | X | X | X | O | X | |
| bcm4375b13,5,6 | 18_38_18_sta | Samsung Galaxy S10 | Rooted + disabled SELinux | X | X | X | O | X | |
| bcm4375b13,5,6 | 18_41_8_9_sta | Samsung Galaxy S20 | Rooted + disabled SELinux | X | X | X | O | X | |
| bcm4389c15,8,9 | 20_82_42_sta (r994653) | Samsung Galaxy S22 Plus | Android 14, Rooted with Magisk | X | X | ||||
| bcm4389c15,8,9 | 20_101_36_2 (r994653) | Google Pixel 7 and 7 Pro | Rooted with Magisk | X | X | ||||
| bcm4389c15,8,9 | 20_101_57 (r1035009) | Google Pixel 7 and 7 Pro | Rooted with Magisk | X | X | ||||
| bcm4398d05,8,9 | 24_671_6_9 (r1031525) | Google Pixel 8 | Rooted with Magisk | X | X | ||||
| bcm6715b05 | 17_10_188_6401 (r808804) | Asus RT-AX86U Pro | Stock firmware 3.0.0.4_388.23565 | / | X | ||||
| qca95004 | 4-1-0_55 | TP-Link Talon AD7200 | Custom LEDE Image |
1 bcm43430a1 was wrongly labeled bcm43438 in the past.
2 use LD_PRELOAD=libnexmon.so instead of LD_PRELOAD=libfakeioctl.so to inject frames through ioctls
3 flash patches need to be 8 bytes long and aligned on an 8 byte boundary
4 802.11ad Wi-Fi chip from first 60 GHz Wi-Fi router Talon AD7200. Patch your firmware using nexmon-arc and run it with our custom LEDE image lede-ad7200
5 Disabled the execution protection (called Execute Never) on region 1, because it interferes with the nexmon code (Permission fault on Section)
6 To use nexutil, you need to deactivate SELinux or set it to permissive
7 See pico-nexmon for example applications using Pico SDK with nexmon.