Bypassing readout protection RDP1 on STM32F4

Can we use the chipwhisperer lite to send flash read commands to external targets like the STM32F4? I want to glitch right after this is performed to bypass read-out protection.

Yeah, that’s possible. In fact, we already have some of the bootloader commands implemented: chipwhisperer/software/chipwhisperer/hardware/naeusb/programmer_stm32fserial.py at develop · newaetech/chipwhisperer · GitHub