Unlocking 2021+ Stellantis 1.5L diesel ECUs (Bosch MD1CS003) no longer requires lifting components or applying voltage fault injection. With Flex update 8.23.0.0 and Korhex tool, you can bypass the TC298 processor security using Electromagnetic Fault Injection (EMFI) right on the bench.

What You Need
- Flexdevice with 20M/ FLS0.20S or FLS0.5S/M license package.
- Korhexglitcher and F mask (you can download and 3D print the positioning mask STL files from the Flex software).
Bench Performance
- Connect Time: ~10 seconds
- Reading: ~2.5 minutes
- Writing: ~2 minutes
- Full Access: Read and write Internal Flash (with checksum) and EEPROM.
Step-by-Step Bench Process
- Connect the Bench Cables: Wire the Korhex adapter and PCB lines to your Flexbox. Power the Korhex tool and check that the blue light is flashing.
- Select Protocol: Open Flex software, select your MD1CS003 vehicle model, and load the TC298 glitch protocol.
- Set the Mask: Fit the Korhex mask onto the ECU board to hold the EMFI tip precisely over the TC298 MCU chip contact area.

- Run Boot Glitch: Execute the glitch command in Flex ECU Tool to clear chip security.
- Read or Write: Once unlocked, use the standard Flex bench menu to back up or write your files.
Covered 2021+ 1.5L Models
- DS 7 Crossback 1.5L BlueHDi
- FIAT Scudo 1.5L MultiJet
- Opel Mokka 1.5L TDCi
- Peugeot 5008 1.5L BlueHDi
- Toyota Proace City 1.5L D4-D
Software Note: Flex V8.23.0.0 also includes a bug fix for write errors on Mercedes Bosch MD1CP001 and MG1CP002 modules.




