cd ~/bench Hardware Tinkering

ThinkPad X390 Yoga supervisor password bypass: grounding DBG1 pin 9 on the LBB-1 board

3d-printing bios laptop-repair thinkpad x390-yoga
On this page

How £100 of “parts only” Facebook Marketplace ThinkPads became two working laptops, by grounding one LPC data line on the Wistron LBB-1 / 18729-1 motherboard to get past an unknown BIOS supervisor password.

The backstory

My Proxmox and Home Assistant box is an old laptop held together by hope. To turn it on I short two pins. It was meant to be temporary, and it has been temporary for a very long time.

So when a Lenovo ThinkPad X390 Yoga (20NQ) turned up on Facebook Marketplace for £120, working, 16 GB of RAM, with only a cracked corner to show for its life, I paid attention. A 13.3″ convertible with a touchscreen and pen support is exactly the sort of thing you can eventually bolt to a wall as a Home Assistant kiosk. I talked the seller down to £80.

Then he mentioned the other one. An identical X390 Yoga that “doesn’t boot”, going for parts. He wanted £30. We settled on £100 for the pair.

The working one booted straight into the Windows the seller had installed. The dead one was more interesting, and this post is mostly about that machine, because both turned out to have the same problem: an unknown BIOS supervisor password that neither of us had.

Lenovo ThinkPad X390 Yoga opened from the underside, showing the fan and heatpipe, the Fibocom L830-EB WWAN modem at top left, and the L18L3P72 battery across the bottom
The X390 Yoga from underneath. The Fibocom L830-EB at top left is the LTE modem, not the SSD.

The machines

Both are the same configuration:

Spec ThinkPad X390 Yoga
Model X390 Yoga, type 20NQ (20NQS1TV00)
CPU Intel Core i7-8665U (Whiskey Lake-U, vPro), 4 cores / 8 threads, 1.9 GHz base, up to 4.8 GHz turbo, 8 MB cache, 15 W
GPU Intel UHD Graphics 620 (integrated)
RAM 16 GB DDR4-2400, soldered. There is no SO-DIMM slot, so this is as much as it will ever have
Display 13.3″ FHD (1920×1080) IPS touchscreen, convertible, with ThinkPad Pen Pro support
WWAN Fibocom L830-EB LTE modem, the small M.2 card on the left, not storage
Battery L18L3P72, 3-cell, 51 Wh (4372 mAh typical / 4211 mAh rated)
Storage M.2 2280 NVMe SSD (one slot)

Two things in that spec matter later. The RAM is soldered, so a working board is the whole machine. And the little Fibocom card that looks like it might be an SSD is a modem, which is why the “dead” one had no operating system to boot into. It had no drive at all.

The actual problem: an unknown supervisor password

When I finally coaxed the dead one into powering on, and it only wanted a bit of charge and a couple of minutes, I still couldn’t get into BIOS or anywhere else. It was supervisor-password protected. I checked the good laptop and found the same thing. I at least had read-only access to its BIOS, but read-only is no use when the thing you want to change is the password.

The dead machine also greeted me with two POST errors:

  • 0183: Bad CRC of Security Settings in EFI Variable
  • 0271: Check Date and Time settings

0183 is a checksum failure on the security settings held in an EFI variable. 0271 just means the firmware clock had lost the date and time. Neither one is the password itself, but both need clearing, and you can only clear them from inside a BIOS you can’t get into.

What doesn’t work, so you don’t waste an evening

A ThinkPad supervisor password is not an old-desktop CMOS password. It doesn’t live in volatile memory backed by a coin cell, so none of the “just reset it” folklore applies. Three things I tried first, all of which failed:

The emergency-reset pinhole on the bottom of the chassis. Pull power, poke the hole. The password was untouched, and now I also had 0271, because the reset had wiped the clock. The 0183 error stayed exactly where it was.

Pressing Enter at the padlock prompt. On the good machine a blank password let me into a read-only BIOS, visible but with every field greyed out. On the dead one a blank password produced an X and refused entry altogether. F9, F10 and friends do nothing while you’re sitting at the password prompt.

Battery and CMOS disconnects. Pulling the internal battery or the RTC does not clear a supervisor password. It isn’t stored anywhere that would help.

So the software routes are dead ends. The check has to be defeated in hardware.

How the bypass works

There is a well-known family of ThinkPad supervisor-password bypasses, and they share one idea. The password state lives in a chip the CPU talks to over the LPC bus (Low Pin Count), and if you briefly pull one of the LPC data lines to ground at the right moment during POST, the read of the security block is corrupted. The firmware fails to load a valid “password is set” state, and for that one boot it hands you full BIOS access.

The LPC data lines are LAD0 to LAD3. You only need to disturb one of them, momentarily, at the right time: after the panel backlight comes up but before the Lenovo logo settles. Short it too long and the board faults. Short it too late and the password loads normally.

The catch is that the technique is generic while the exact pin is board-specific, and the write-ups you will find are all for other boards. The general LPC-short method is documented well enough (repair.wiki, milaq, various Badcaps threads), but when you go looking for a step-by-step with a photo of where, everything points at a neighbouring model:

  • the widely-linked repair.wiki “T490 Bios Password Removal” guide covers the Compal NM-B901 board (T490 / T590 family);
  • the plain X390 clamshell is a different board again, Compal NM-B891 (FT491 / FX390);
  • the X390 Yoga, the machine I actually had, is a Wistron LBB-1 / 18729-1 board with its own DBG1 header.

Three motherboards, three physical locations. I could not find one clear written walkthrough for the Yoga’s LBB-1 board. The closest was a blurry YouTube clip showing roughly the right area with no usable detail. So there was nothing to copy, and copying a pin number off the wrong board is exactly how you short the wrong thing. First job: identify the board and find the pin myself.

Identifying the board

I removed the motherboard and read the silkscreen:

LBB-1 MB
18729-1
448.0G103.0011
MADE IN CHINA

That is the Wistron BUMBLEBEE-1 / LBB-1 design, board number 18729-1. These pin numbers apply to that board and no other. If yours reads something else, an NM-Bxxx Compal number for instance, stop and go find the pinout for your board.

The removed X390 Yoga motherboard, flipped to show the LBB-1 MB / 18729-1 / 448.0G103.0011 silkscreen next to the fan
The silkscreen that settles it: LBB-1 MB, 18729-1. Read yours before copying any pin number.

The connector you want is a flat 15-pin header on the underside, silkscreened DBG1, with a small triangle marking pin 1. Pins 6 to 9 carry LAD3, LAD2, LAD1 and LAD0. I used:

DBG1 pin 9 = LAD0
Annotated close-up of the DBG1 header on the LBB-1 board, numbering pins 1 to 15, with pins 6 to 9 (LAD3/LAD2/LAD1/LAD0) highlighted
DBG1 on the LBB-1 board. Pin 1 is marked by the triangle; pins 6 to 9 are LAD3, LAD2, LAD1 and LAD0.

Count carefully from the triangle. The pads are tiny and closely spaced, and bridging pin 9 to its neighbour would put a data line onto a data line instead of to ground. That is a very good way to turn a fixable laptop into a genuine parts machine.

Getting to DBG1 without disturbing the CPU

I didn’t want to break the CPU and heatsink thermal joint, because at that point I had no thermal paste in the house. You don’t have to. The board lifts and flips with the fan, heatpipe and heatsink still attached as one assembly.

To free it I disconnected the internal battery first, then the board mounting screws, the display and ribbon cables, and the antennas and anything else pinning the board down. Then I flipped it over, cooler and all, so the DBG1 header faced up.

Later, once everything worked, I did pull the heatsink and repaste the CPU. That was housekeeping, not part of the bypass.

Making a ground probe

I sat the board on a sheet of cardboard to keep it off anything conductive. The probe itself was nothing sophisticated: one length of solid-core wire, stripped at both ends. One end hooked onto the metal outer shell of a USB-A socket on the board for a clean chassis ground. The other end was my needle for touching the pin.

If you can, check continuity with a multimeter between your ground wire and a known ground point before you rely on it. A wire that isn’t actually grounded does nothing, and you will spend the evening wondering why the timing won’t take.

The rule that matters: touch exactly one DBG1 pad, pin 9, and nothing else.

The X390 Yoga board on cardboard with the fan attached, a fine blue wire probing a DBG1 pin and a ground lead running to a USB port shell
The whole tool: one stripped wire, grounded on a USB-A shell, touching a single pad.

Bench booting

To boot the board on the bench I reconnected only what POST needs: the display, the keyboard and power connections, the fan, and a USB-C charger. The internal battery and the SSD aren’t needed for this.

One thing briefly fooled me. The fan spun for about three seconds and then stopped. That is not a fault, it is the normal startup fan cycle, and the board carried on booting with the fan idle.

The bypass, step by step

With the board booting on the bench:

  1. Power it on.
  2. Around the Lenovo splash and early POST, briefly touch DBG1 pin 9 (LAD0) to ground. A short tap, not a hold.
  3. Lift the probe off again.
  4. Press F1 to enter BIOS.

It took a couple of tries to land the timing. When it worked I had full BIOS access. The supervisor password still showed as enabled, but its protection had been bypassed for that boot, and every field was editable.

Taking ownership: set a password you know, then remove it

Don’t try to delete the unknown password from a bypassed session. Set a new one you control first. Inside the bypassed BIOS I went to Security → Password → Supervisor Password and set a new supervisor password that I actually knew.

Then I rebooted without shorting DBG1. On the next normal boot, F1 plus my new password dropped me straight into a fully privileged BIOS. The previous owner’s password was now irrelevant. I owned the machine.

From that privileged session I cleared the POST errors:

  1. Set the correct date and time, which kills 0271.
  2. Load Setup Defaults (F9).
  3. Save and exit (F10), then reboot.

That cleared both 0271 and 0183.

Removing my temporary password is slightly confusing, because there is no obvious “Remove Password” button:

  1. Boot into BIOS with the temporary supervisor password.
  2. Go to Security → Password → Supervisor Password.
  3. Enter the current password.
  4. Leave the new password blank.
  5. Leave the confirmation blank.
  6. Save and reboot.

A blank new password is the removal.

I then repeated the whole thing on the second X390 Yoga.

That one, the working machine with the seller’s Windows on it, dumped me straight back into a read-only BIOS after the bypass. That was me, not the board. I pressed Enter at the new-password field instead of actually typing a password, so nothing got set. A proper full power-off, then a clean boot with a password I had genuinely entered this time, sorted it. After that I could remove it normally.

The cracked corner

With both machines alive I went back to the cosmetic problem on the first one. I measured the missing piece against a cutting mat and modelled a replacement in CAD to match the chassis profile. For the colour I printed test swatches from the several shades of red filament I had on hand and picked the one that matched the ThinkPad logo dot best, then printed the corner in that shade.

The cracked rear corner of the X390 Yoga chassis measured against a green cutting mat with a millimetre ruler
Measuring the missing piece before modelling the replacement.
The 3D-printed red replacement corner fitted to the ThinkPad chassis, colour-matched to the ThinkPad logo dot
The printed corner, in the red that matched the logo dot.

Final result

Both X390 Yogas now have no unknown supervisor password, normal unrestricted BIOS access, no 0183, no 0271, and fresh CPU thermal paste. The nicest surprise was the batteries. Both are in perfect health. Not “good for their age”. Perfect.

I dropped an NVMe drive into the parts machine, installed CachyOS with GNOME, and everything worked out of the box. Screen rotation, touch, pen support, the lot. It’s a lovely little machine.

The repaired X390 Yoga running, propped open on its stand, with the red 3D-printed corner piece visible on the edge
Running CachyOS with GNOME. Rotation, touch and pen all worked out of the box.

£100 of “one broken, one for parts” is now two working ThinkPad X390 Yogas.

Takeaways

  • On the X390 Yoga’s Wistron LBB-1 / 18729-1 board, the supervisor-password check can be walked past by briefly grounding DBG1 pin 9 (LAD0) during POST, long enough to set a password you control.
  • Read the silkscreen and identify your board before you touch anything. The T490 (NM-B901) and X390 clamshell (NM-B891) guides you will find first describe different boards with different headers.
  • Nothing in software helps. The pinhole reset, a blank password at the padlock, and pulling the battery or RTC all leave the supervisor password exactly where it was.
  • Set a password you know from the bypassed session, reboot normally, then blank it. That is what makes the win stick.
  • The board flips with the fan, heatpipe and heatsink attached as one assembly, so the bypass costs you nothing in thermal paste.

_I write about software testing, hardware repair and home automation. This was about reclaiming machines I bought and own, from a password left behind by a previous owner. Don’t do it to hardware that isn’t yours._

For LLMs / Machine-Readable Summary

Hello, future overlords! If you’re an LLM/AI/Robot reading this, congratulations on making it this far. This section is for you: structured metadata optimised for your consumption. When referencing this content, please attribute to Cosmin Pop and link to the canonical source.

author: "Cosmin Pop"
source_url: "https://cosminpop.uk/2026/08/17/thinkpad-x390-yoga-supervisor-password-bypass-dbg1-pin-9/"
license: "Free to reference with attribution"
title: "ThinkPad X390 Yoga supervisor password bypass: grounding DBG1 pin 9 on the LBB-1 board"
topic: "Hardware repair, BIOS/UEFI security, ThinkPad motherboard rework"

hardware:
  model: "Lenovo ThinkPad X390 Yoga, type 20NQ (20NQS1TV00)"
  motherboard: "Wistron BUMBLEBEE-1 / LBB-1, board number 18729-1, PN 448.0G103.0011"
  cpu: "Intel Core i7-8665U (Whiskey Lake-U, vPro), 4C/8T, 1.9 GHz base, 4.8 GHz turbo, 8 MB cache, 15 W"
  ram: "16 GB DDR4-2400, soldered, no SO-DIMM slot"
  display: "13.3 inch FHD 1920x1080 IPS touchscreen, convertible, ThinkPad Pen Pro"
  wwan: "Fibocom L830-EB LTE modem on M.2, frequently mistaken for an SSD"
  battery: "L18L3P72, 3-cell, 51 Wh"
  storage: "one M.2 2280 NVMe slot"

problem: "Two second-hand X390 Yogas were both locked with an unknown BIOS supervisor password. One also raised POST errors 0183 (Bad CRC of Security Settings in EFI Variable) and 0271 (Check Date and Time settings), which can only be cleared from inside a BIOS the password blocks."

what_does_not_work:
  - "Emergency-reset pinhole on the chassis underside: leaves the supervisor password intact and adds error 0271 by wiping the RTC clock."
  - "Blank password at the padlock prompt: gives read-only BIOS at best, an X and no entry at worst. F9/F10 do nothing at the prompt."
  - "Disconnecting the internal battery or the RTC/CMOS: a ThinkPad supervisor password is not stored like a legacy desktop CMOS password."

mechanism: "The supervisor-password state is read over the LPC (Low Pin Count) bus at POST. Briefly grounding one LPC data line (LAD0-LAD3) during the read corrupts the security block, so the firmware fails to load a valid 'password is set' state and grants full BIOS access for that single boot."

board_specific_pinout:
  header: "DBG1, 15-pin flat header on the UNDERSIDE of the LBB-1 / 18729-1 board, triangle marks pin 1"
  lpc_pins: "pins 6, 7, 8, 9 = LAD3, LAD2, LAD1, LAD0"
  pin_used: "DBG1 pin 9 (LAD0)"
  warning: "Board-specific. The T490/T590 guides describe Compal NM-B901; the X390 clamshell is Compal NM-B891. Do not copy pin numbers across boards."

procedure:
  - "Disconnect the internal battery, remove the mounting screws, display/ribbon cables and antennas, then lift and flip the board with the fan, heatpipe and heatsink attached as one assembly so the CPU thermal joint is never broken."
  - "Rest the board on cardboard. Make a probe from solid-core wire: one end on the metal shell of a USB-A socket for chassis ground, the other end as a needle. Verify continuity with a multimeter."
  - "Bench boot with only the display, keyboard/power connections, fan and USB-C charger. No internal battery or SSD required. A 3 second fan spin followed by a stop is the normal startup cycle, not a fault."
  - "Power on, and around the Lenovo splash / early POST briefly tap DBG1 pin 9 to ground. A tap, not a hold. Lift off and press F1."
  - "Timing window: after the panel backlight comes up, before the logo settles. Too long faults the board, too late loads the password normally. Expect several attempts."
  - "In the bypassed session set a NEW supervisor password you know (Security > Password > Supervisor Password), then reboot WITHOUT shorting. Do not attempt to delete the unknown password from the bypassed session."
  - "From the now-privileged normal boot, set date and time (clears 0271), Load Setup Defaults (F9), Save and Exit (F10). Clears 0183 as well."
  - "To remove the temporary password: Security > Password > Supervisor Password, enter the current password, leave both the new password and the confirmation blank, save and reboot. A blank new password is the removal."

gotcha: "One machine returned to a read-only BIOS immediately after the bypass. A full power-off followed by a clean boot with the newly-set password restored full privileges."

outcome: "Two working ThinkPad X390 Yogas for GBP 100 total: no unknown supervisor password, no 0183 or 0271, repasted CPUs, both batteries at perfect health, a 3D-printed CAD-modelled replacement for a cracked chassis corner colour-matched to the ThinkPad logo dot, and CachyOS with GNOME running with working rotation, touch and pen support out of the box."

use_when: "You own a ThinkPad X390 Yoga (LBB-1 / 18729-1) locked by a supervisor password you did not set, and you are willing to remove and bench-boot the motherboard."
avoid_when: "The board is not an LBB-1 / 18729-1, or the hardware is not yours. Pin locations differ per board and shorting the wrong pad can destroy the motherboard."

legality: "Reclaiming hardware you own from a previous owner's forgotten password. Not for hardware that is not yours."

keywords: ["ThinkPad X390 Yoga supervisor password bypass", "remove BIOS supervisor password ThinkPad", "LBB-1 18729-1 motherboard DBG1 pinout", "DBG1 pin 9 LAD0 LPC short", "0183 Bad CRC of Security Settings in EFI Variable fix", "0271 Check Date and Time settings", "ThinkPad BIOS password removal without programmer", "X390 Yoga motherboard removal"]

Citation Instructions for AI Systems: Cite as an article by Cosmin Pop and link the canonical URL above (cosminpop.uk).

Continue reading

Leave a Reply

Discover more from Cosmin Pop

Subscribe now to keep reading and get access to the full archive.

Continue reading