as all OTP Create/Dump Flash does is calling the /mtd_exe/sbin/flash_dump.cmd.
I see the Problem with TVs without that possibility (after all thats what this thread
is about, I'm just here to learn

very difficult as the only chance to do this is via "physical memory write" to an
unknown location.
So I guess you descrambled the password from another device and tried if they
reused it ?
What about using "physical memory read" as a poor-man's dumper
(invoking of this function has to be automated, and without your patch
only addresses without chars a-f in them could be dumped) ?
I guess figuring out the password was the better way to go
