Speed Configuration & Limiters¶
How top speed is governed on the E-series is a frequent point of confusion, because the app exposes a single "speed limit" control while the actual cap comes from a different, read-only register. This page separates the two, lists every speed/gear register that exists in the config, and records what a live E125S actually does.
The two independent caps¶
| Register | Units | Writable? | Role | |
|---|---|---|---|---|
| User speed lock | setLimitSpeed / rLimitSpeed — DIS 0x93 |
whole km/h | Yes (enum) | The app's "speed safety lock" |
| Rated / factory cap | rRatedSpeed / rMaxSpeed — DIS 0x48 |
×10 (450 = 45.0) | No (read-only) | Type-approval / homologation cap |
The effective top speed is min(rated, lock). Raising the user lock to its
maximum does nothing if the rated cap is lower — which is exactly what a Dutch
45 km/h E125S shows: lock can be set to 60, but rRatedSpeed = 450 (45.0) holds.
The lock register is whole km/h, not 0.1 km/h
setLimitSpeed writes the km/h value directly. Sending 58 02 (600)
expecting "60 km/h" is wrong — the correct payload for 60 is 3C 00. The
×10 scaling applies to the rated/current-speed readings, not the lock.
User speed lock — values & payloads¶
Speed safety lock — setLimitSpeed / rLimitSpeed, DIS register 0x93. Values are whole km/h (the config writes the km/h value directly — not 0.1 km/h units).
| Setting | Value written | On-wire payload (u16 LE) |
|---|---|---|
| off / no limit | 0 | 00 00 |
| 25 km/h | 25 | 19 00 |
| 35 km/h | 35 | 23 00 |
| 45 km/h | 45 | 2D 00 |
| 60 km/h | 60 | 3C 00 |
Read back with rLimitSpeed (DIS 0x93, 2 bytes). The rated/factory cap is a separate, read-only register rRatedSpeed/rMaxSpeed (DIS 0x48, stored ×10 — e.g. 450 = 45.0 km/h). Effective top speed = min(rated, lock).
Every speed/gear register in the config¶
Generated from the config package for the reference family. Note this is a superset — the config carries registers for the whole E-family, and a given model may not implement all of them (see the live findings below).
Every speed/gear/limit register present in the config for this family (a superset — some, like the MCU gear bank, are absent on specific models).
| module:index | name | ops | len |
|---|---|---|---|
dis:0x24 |
rSigMaxSpeed |
read | 2 |
dis:0x26 |
rSpeed |
read | 2 |
dis:0x27 |
rAveSpeed |
read | 2 |
dis:0x48 |
rRatedSpeed |
read | 2 |
dis:0x48 |
rMaxSpeed |
read | 2 |
dis:0x5E |
rNos |
read | 2 |
dis:0x74 |
rCfgMode |
read | 2 |
dis:0x74 |
setCfgMode |
writeNR | |
dis:0x7E |
rGearValue1 |
read | 2 |
dis:0x7E |
setGearValue1 |
writeNR | |
dis:0x7F |
rGearValue2 |
read | 2 |
dis:0x7F |
setGearValue2 |
writeNR | |
dis:0x93 |
rLimitSpeed |
read | 2 |
dis:0x93 |
setLimitSpeed |
writeNR | |
dis:0x93 |
setLimitSpeed_0 |
writeNR | |
dis:0x93 |
setLimitSpeed_25 |
writeNR | 25 |
dis:0x93 |
setLimitSpeed_45 |
writeNR | 45 |
dis:0x93 |
setLimitSpeed_60 |
writeNR | 60 |
dis:0x93 |
setLimitSpeed_35 |
writeNR | 35 |
dis:0xA4 |
rGearUnlockMile |
read | 4 |
fl-apl:0x8C |
rFL-APLModelSpeed1 |
read | 2 |
fl-apl:0x8C |
setFL-APLModeSpeed1 |
write | |
fl-apl:0x8C |
setFL-APLModeSpeed1Bit |
write | |
fl-apl:0x9B |
rFL-APLModelSpeed2 |
read | 2 |
fl-apl:0x9B |
setFL-APLModelSpeed2 |
write | |
fl-apl:0x9B |
setFL-APLModelSpeed2Bit |
write | |
fl-apl:0xAA |
rFL-APLModelSpeed3 |
read | 2 |
fl-apl:0xAA |
setFL-APLModelSpeed3 |
write | |
fl-apl:0xAA |
setFL-APLModelSpeed3Bit |
write | |
fl-apl:0xB9 |
rFL-APLModelSpeed4 |
read | 2 |
fl-apl:0xB9 |
setFL-APLModelSpeed4 |
write | |
fl-apl:0xB9 |
setFL-APLModelSpeed4Bit |
write | |
mcu:0x09 |
rMCUMaxSpeed |
read | 2 |
mcu:0x22 |
rGearData1 |
read | 32 |
mcu:0x22 |
wGearData1 |
write | |
mcu:0x22 |
setAccMap |
writeNR | |
mcu:0x2C |
setGearEnergy |
writeNR | |
mcu:0x2D |
setGearAccSpeed |
writeNR | |
mcu:0x2E |
setGearAccSensitivity |
writeNR | |
mcu:0x2F |
setGearTcs |
writeNR | |
mcu:0x30 |
setGearNitroSpeed |
writeNR | |
mcu:0x31 |
setGearTopSpeed |
writeNR | |
mcu:0x3A |
rGearData2 |
read | 32 |
mcu:0x3A |
wGearData2 |
write | |
mcu:0x3A |
setAccMap2 |
writeNR | |
mcu:0x44 |
setGearEnergy2 |
writeNR | |
mcu:0x45 |
setGearAccSpeed2 |
writeNR | |
mcu:0x46 |
setGearAccSensitivity2 |
writeNR | |
mcu:0x47 |
setGearTcs2 |
writeNR | |
mcu:0x48 |
setGearNitroSpeed2 |
writeNR | |
mcu:0x49 |
setGearTopSpeed2 |
writeNR | |
mcu:0x52 |
rSpeedIntensity |
read | 2 |
mcu:0x52 |
setSpeedIntensity |
write | 2 |
mcu:0x53 |
setSpeedSafeLock |
write | |
mcu:0x53 |
rSpeedSafeLock |
read | 2 |
mcu:0x55 |
rTCS |
read | 2 |
mcu:0x55 |
setTCS |
write | 2 |
mcu:0x56 |
rSlope |
read | 2 |
mcu:0x56 |
setSlope |
write | 2 |
tft:0x03 |
rGearNameM1 |
read | |
tft:0x04 |
setGearNameM1 |
write | |
tft:0x07 |
rGearNameM2 |
read | |
tft:0x08 |
setGearNameM2 |
write |
Live findings (E125S, full register sweep)¶
Observed on a Dutch 45 km/h E125S with a complete 0x00–0xFF sweep of every
controller while powered on:
- No MCU gear subsystem. The MCU (target
0x02) answers only its part number (0x00/0x10) — none of therGearData*/setGearTopSpeed/rMCUMaxSpeedregisters respond, powered on or off. The gear commands in the config exist for other E-family models; on the E125S they are dead ends. - A dormant 50.0 value in the ECU. The ECU (target
0x09) holds an undocumented config block around register0xDF; word0xE3=0x01F4= 500 (50.0 km/h), whilerRatedSpeedstays at 450 (45.0). The app never reads or writes this block. It is the most likely target of a dealer "50 km/h" change, alongside the DIS rated value. - Power state lives in
rMainPower(ECU0x03): bit 3 (0x08) = on. See Board availability.
Interoperability & owner control
This documents how an owner's own vehicle reports and stores its speed
configuration over the BLE interface. The rated cap (rRatedSpeed) is
read-only over BLE and is not modified by any command documented here.