Skip to content

Speed Configuration & Limiters

How top speed is governed on the E-series is a frequent point of confusion, because the app exposes a single "speed limit" control while the actual cap comes from a different, read-only register. This page separates the two, lists every speed/gear register that exists in the config, and records what a live E125S actually does.


The two independent caps

Register Units Writable? Role
User speed lock setLimitSpeed / rLimitSpeed — DIS 0x93 whole km/h Yes (enum) The app's "speed safety lock"
Rated / factory cap rRatedSpeed / rMaxSpeed — DIS 0x48 ×10 (450 = 45.0) No (read-only) Type-approval / homologation cap

The effective top speed is min(rated, lock). Raising the user lock to its maximum does nothing if the rated cap is lower — which is exactly what a Dutch 45 km/h E125S shows: lock can be set to 60, but rRatedSpeed = 450 (45.0) holds.

The lock register is whole km/h, not 0.1 km/h

setLimitSpeed writes the km/h value directly. Sending 58 02 (600) expecting "60 km/h" is wrong — the correct payload for 60 is 3C 00. The ×10 scaling applies to the rated/current-speed readings, not the lock.

User speed lock — values & payloads

Speed safety locksetLimitSpeed / rLimitSpeed, DIS register 0x93. Values are whole km/h (the config writes the km/h value directly — not 0.1 km/h units).

Setting Value written On-wire payload (u16 LE)
off / no limit 0 00 00
25 km/h 25 19 00
35 km/h 35 23 00
45 km/h 45 2D 00
60 km/h 60 3C 00

Read back with rLimitSpeed (DIS 0x93, 2 bytes). The rated/factory cap is a separate, read-only register rRatedSpeed/rMaxSpeed (DIS 0x48, stored ×10 — e.g. 450 = 45.0 km/h). Effective top speed = min(rated, lock).


Every speed/gear register in the config

Generated from the config package for the reference family. Note this is a superset — the config carries registers for the whole E-family, and a given model may not implement all of them (see the live findings below).

Every speed/gear/limit register present in the config for this family (a superset — some, like the MCU gear bank, are absent on specific models).

module:index name ops len
dis:0x24 rSigMaxSpeed read 2
dis:0x26 rSpeed read 2
dis:0x27 rAveSpeed read 2
dis:0x48 rRatedSpeed read 2
dis:0x48 rMaxSpeed read 2
dis:0x5E rNos read 2
dis:0x74 rCfgMode read 2
dis:0x74 setCfgMode writeNR
dis:0x7E rGearValue1 read 2
dis:0x7E setGearValue1 writeNR
dis:0x7F rGearValue2 read 2
dis:0x7F setGearValue2 writeNR
dis:0x93 rLimitSpeed read 2
dis:0x93 setLimitSpeed writeNR
dis:0x93 setLimitSpeed_0 writeNR
dis:0x93 setLimitSpeed_25 writeNR 25
dis:0x93 setLimitSpeed_45 writeNR 45
dis:0x93 setLimitSpeed_60 writeNR 60
dis:0x93 setLimitSpeed_35 writeNR 35
dis:0xA4 rGearUnlockMile read 4
fl-apl:0x8C rFL-APLModelSpeed1 read 2
fl-apl:0x8C setFL-APLModeSpeed1 write
fl-apl:0x8C setFL-APLModeSpeed1Bit write
fl-apl:0x9B rFL-APLModelSpeed2 read 2
fl-apl:0x9B setFL-APLModelSpeed2 write
fl-apl:0x9B setFL-APLModelSpeed2Bit write
fl-apl:0xAA rFL-APLModelSpeed3 read 2
fl-apl:0xAA setFL-APLModelSpeed3 write
fl-apl:0xAA setFL-APLModelSpeed3Bit write
fl-apl:0xB9 rFL-APLModelSpeed4 read 2
fl-apl:0xB9 setFL-APLModelSpeed4 write
fl-apl:0xB9 setFL-APLModelSpeed4Bit write
mcu:0x09 rMCUMaxSpeed read 2
mcu:0x22 rGearData1 read 32
mcu:0x22 wGearData1 write
mcu:0x22 setAccMap writeNR
mcu:0x2C setGearEnergy writeNR
mcu:0x2D setGearAccSpeed writeNR
mcu:0x2E setGearAccSensitivity writeNR
mcu:0x2F setGearTcs writeNR
mcu:0x30 setGearNitroSpeed writeNR
mcu:0x31 setGearTopSpeed writeNR
mcu:0x3A rGearData2 read 32
mcu:0x3A wGearData2 write
mcu:0x3A setAccMap2 writeNR
mcu:0x44 setGearEnergy2 writeNR
mcu:0x45 setGearAccSpeed2 writeNR
mcu:0x46 setGearAccSensitivity2 writeNR
mcu:0x47 setGearTcs2 writeNR
mcu:0x48 setGearNitroSpeed2 writeNR
mcu:0x49 setGearTopSpeed2 writeNR
mcu:0x52 rSpeedIntensity read 2
mcu:0x52 setSpeedIntensity write 2
mcu:0x53 setSpeedSafeLock write
mcu:0x53 rSpeedSafeLock read 2
mcu:0x55 rTCS read 2
mcu:0x55 setTCS write 2
mcu:0x56 rSlope read 2
mcu:0x56 setSlope write 2
tft:0x03 rGearNameM1 read
tft:0x04 setGearNameM1 write
tft:0x07 rGearNameM2 read
tft:0x08 setGearNameM2 write

Live findings (E125S, full register sweep)

Observed on a Dutch 45 km/h E125S with a complete 0x000xFF sweep of every controller while powered on:

  • No MCU gear subsystem. The MCU (target 0x02) answers only its part number (0x00/0x10) — none of the rGearData* / setGearTopSpeed / rMCUMaxSpeed registers respond, powered on or off. The gear commands in the config exist for other E-family models; on the E125S they are dead ends.
  • A dormant 50.0 value in the ECU. The ECU (target 0x09) holds an undocumented config block around register 0xDF; word 0xE3 = 0x01F4 = 500 (50.0 km/h), while rRatedSpeed stays at 450 (45.0). The app never reads or writes this block. It is the most likely target of a dealer "50 km/h" change, alongside the DIS rated value.
  • Power state lives in rMainPower (ECU 0x03): bit 3 (0x08) = on. See Board availability.

Interoperability & owner control

This documents how an owner's own vehicle reports and stores its speed configuration over the BLE interface. The rated cap (rRatedSpeed) is read-only over BLE and is not modified by any command documented here.