What Is UART? Find a Serial Port and Read the Boot Log
What is UART? The serial port hidden on circuit boards. Find TX, RX and GND, work out the baud rate and safely read the boot console of a device you own.
UART (Universal Asynchronous Receiver-Transmitter) is the simplest serial port there is: two data wires, a ground, and a device that tells you in plain text what it is doing as it boots. You will find it on a large share of routers, set-top boxes, cameras and IoT devices, often as four discreet pads on the board. Finding it, connecting to it and reading the boot console is the "hello world" of hardware hacking.
The ideal target for this guide is an old router you own, picked up second-hand for a few euros. Everything below is done on your own hardware.
UART at a glance
A UART link joins two chips with three useful wires.
Device (router) USB-UART adapter
┌──────────────┐ ┌──────────────┐
│ TX ─┼──────────────────►┼─ RX │
│ RX ─┼◄──────────────────┼─ TX │
│ GND ─┼───────────────────┼─ GND │
│ VCC │ (do not connect) │ VCC │
└──────────────┘ └──────────────┘
- TX (transmit): the pin the device sends data on.
- RX (receive): the pin it listens on.
- GND: ground, the shared voltage reference for both sides.
- VCC: the chip's supply voltage, often present on the header. Leave it unconnected.
One side's TX goes to the other side's RX, and vice versa. There is no shared clock: both sides simply have to agree on the same speed, the baud rate, in bits per second. The most common frame format is "8N1": 8 data bits, no parity, 1 stop bit.
What you need
| Tool | What it's for | Note |
|---|---|---|
| USB-UART adapter (CP2102, CH340, FT232…) | Connects the serial port to your computer | Pick one that runs at 3.3 V |
| Multimeter | Finds ground and measures voltages | Any model with a continuity beeper will do |
| Logic analyser | Shows the data and measures the baud rate | Optional, but very handy |
| Jumper wires, test hooks | Connect to the pins | A header to solder if the pads are bare |
Safety: voltage levels and power
Two rules prevent most of the damage.
- Check the voltage before you connect. Most modern boards run at 3.3 V, some at 1.8 V, a few older ones at 5 V. An adapter set to 5 V driving an RX pin designed for 3.3 V can damage the device's chip. Measure first, then set your adapter to match (often a 3.3 V / 5 V jumper). For 1.8 V you need an adapter that supports it, or a level shifter.
- Never connect VCC. The device runs from its own power supply. Wiring the adapter's VCC as well creates two power sources fighting each other and can damage the device, the adapter or your computer's USB port. Only GND, TX and RX get connected.
Add basic bench sense: unplug the device while you move wires, stay away from any internal mains power supply if the case contains one, and never connect an RS-232 port (old DB9 connectors at roughly ±12 V) to a TTL adapter.
Finding the pins (multimeter, logic analyser)
Spot the header
Open the case and look for a row of 3 to 5 pads or pins, often near the main processor. They are sometimes labelled ("J1", "CON2", "TX RX GND"), sometimes not. A row of four is the most common case. Take a sharp photo of both sides of the board: it will be your map.
Identify each pin with a multimeter
Work in this order.
- GND, device off. Set the multimeter to continuity. Put one probe on a known ground (a metal shield, the shell of a USB or Ethernet connector) and test each pin. The one that beeps is ground.
- VCC, device on. Switch to DC voltage, black probe on GND. The pin that shows a steady voltage (3.3 V, say) from power-on and never moves is probably VCC. Note the value: that is the board's logic level.
- TX, during boot. Measure the remaining pins right after power-on. TX is sending the boot log, so its voltage fluctuates for a few seconds before settling high, because an idle UART line sits at logic high.
- RX, by elimination. The last pin is usually steady, either high or close to 0 V depending on the board.
Confirm with a logic analyser
If you have a logic analyser, connect its ground to GND and one channel to the suspected TX pin, start a capture in PulseView, then power the device on. You should see bursts of transitions during boot. That confirms TX, and it lets you measure the baud rate too. Our PulseView logic analyser tutorial covers installation and decoding step by step.
Finding the baud rate
No magic here: either you guess from the usual values or you measure.
Try the common values
Most embedded Linux devices use 115200 baud. After that come 57600, 38400, 19200 and 9600. The wrong setting gives you garbage, the right one gives you readable text.
Measure the shortest bit
In the logic analyser capture, zoom into a burst and measure the narrowest pulse: that is the length of one bit. The baud rate is one divided by that duration.
| Measured bit length | Baud rate |
|---|---|
| ≈ 8.7 µs | 115200 |
| ≈ 17.4 µs | 57600 |
| ≈ 26 µs | 38400 |
| ≈ 52 µs | 19200 |
| ≈ 104 µs | 9600 |
Then add PulseView's UART decoder at that baud rate: if text appears, you're done.
Connecting and reading the boot log
Wire it up with the device powered off:
- device GND to adapter GND;
- device TX to adapter RX;
- device RX to adapter TX;
- VCC left unconnected.
On Linux, find the adapter and open a serial terminal:
sudo dmesg | tail # the adapter shows up, e.g. ttyUSB0
ls /dev/ttyUSB*
sudo usermod -aG dialout $USER # once, then log out and back in
picocom -b 115200 /dev/ttyUSB0 # exit: Ctrl-A then Ctrl-X
Or with screen:
screen /dev/ttyUSB0 115200 # exit: Ctrl-A then K
On macOS the port is usually /dev/tty.usbserial-… or /dev/tty.usbmodem…. On Windows, PuTTY in "Serial" mode with the COM port shown in Device Manager does the job.
Now power the device on. If everything is right, text scrolls past. This is what the start of a Linux router's boot log typically looks like (simplified example):
U-Boot 2012.10 (...)
DRAM: 64 MiB
Flash: 8 MiB
Hit any key to stop autoboot: 1
Starting kernel ...
Linux version 3.10.x ...
Troubleshooting in one line each: garbage text, change the baud rate; nothing at all, swap TX and RX; random characters even at the right baud rate, check the ground.
What it reveals, and where to stop
What you learn about your device
The boot console is a goldmine of information about your own hardware:
- the bootloader (often U-Boot, the program that loads the operating system) and its version;
- the Linux kernel version, sometimes with its build date, which tells you whether the device is up to date;
- the flash partition table, the first step to understanding where the firmware lives;
- sometimes a login prompt, or even an open shell, a sign the manufacturer left a debug configuration in place.
A word of caution: if the bootloader lets you interrupt the boot, reading information is fine, but avoid any command that writes to or erases flash until you have a backup. It is the fastest way to turn a router into a paperweight. The natural next step, dumping and analysing the firmware, is covered in our guide to firmware extraction for beginners.
Where to stop
This whole guide assumes a device you own. A few clear limits:
- No third-party devices. Opening the broadband router your ISP lent you (it often remains their property) or your employer's equipment without written permission is not an exercise. Unauthorised access to a computer system is a criminal offence across Europe, for instance under the UK's Computer Misuse Act 1990 or article 323-1 of the French Penal Code.
- No reuse. A password or key found on your device must not be used to log into an online service or other people's devices.
- Report rather than publish. If you find a real vulnerability in a product still on sale, contact the manufacturer before going public. Your national CERT can help coordinate if the vendor doesn't respond.
Practise without taking anything apart
If you would rather start without opening a case or soldering, our CTF puzzles are designed for exactly that. The Firmware Dump, planned for 2028, puts a clearly exposed memory chip on a board for you to read with the included USB programmer, with three levels and nothing to solder. It is on the waitlist: sign up to be notified. And to watch your first UART frames, an 8-channel logic analyser that works with PulseView is the most versatile tool on the bench.
Frequently asked questions
What is the difference between UART and RS-232?
UART describes how the bits are sent (one wire to transmit, one to receive, no clock). On a circuit board it runs at TTL logic levels of 3.3 V or 1.8 V. RS-232 uses the same idea at much higher voltages, around ±12 V, on old DB9 ports. Never connect a TTL adapter to an RS-232 port.
Do I need to solder to connect to a UART port?
Not always. Some devices already have header pins fitted. Otherwise test hooks, grabbers or spring-loaded pogo pins can do the job, but soldering a header remains the most reliable option on bare pads.
Why do I only see garbage characters?
Almost always the wrong baud rate. Try 115200, then 57600, 38400 and 9600. If nothing changes, check that TX and RX aren't swapped and that the grounds are connected.
Is it legal to open a device and read its serial console?
On a device you own, opening the case and reading its console is tinkering and learning, although it may void the warranty. Using what you find to access a system or device that isn't yours without permission is a criminal offence.