Well reading the flash was a bit fussy, but after some hot air and a ZIF socket here’s a dump of the firmware for those interested: 50.5 MB file on MEGA
I’ve got more flash chips on the way, so hopefully it’s time to crack this image open and start investigating. Next stop, binwalk!
Update 20250605:
Minor update, I’ve obtained two more remotes. I’ve managed to dump the flash from these in board by using a better quality probe and some precautions around introducing errant noise.
As observed in thread: Integration in HA of new Mini 3.5” Smart Control Panel TPP06 the passwords appear to be unique per device.
I’m still poking around in firmware when I have time. I’ll probably move further discussion to the thread linked above to address the common elements around figuring out how the passwords are generated etc. Getting to a stage where some sort of shell is available to anyone without having to have specialized tools is probably the first thing to address.