Thanks for writing this up! Very interesting.
Looks like the procedure in README.md is based on soldering something onto J9 to get to the uboot prompt, copying the firmware off the camera, and copying altered firmware back.
Has anyone tried altering a .pak file and uploading it through the camera's web UI? I don't know if Reolink uses signed firmware or something to prevent this. It'd be nice to have a way of getting ssh access without any hardware modification.