Question About Korean Local Ringback Tone in EC25EFAR08A05M4G_KR Firmware

Dear Quectel Support Team,

We are currently using the EC25 module with the following firmware:

EC25EFAR08A05M4G_KR_01.001.01.001

While analyzing this firmware package, we found audio resources that appear to be related to local ringback tones, including a file named ringing_korea.wav.

We also noticed that the release notes for the EC25EFAR08A04M4G_KR version mention the following item:

“Supported playing local ringback tone based on the voice over USB function.”

Because of this, we would like to understand how the Korean local ringback tone function is intended to be used.

We performed some tests using AT commands through the OpenVox gateway’s module toolkit. The command below is supported by the module:

AT+QLTONE=?

The module returned:

+QLTONE: (0,1),(100-4000),(0-1000),(0-1000),(0-15300000)

We also tested:

AT+QLTONE=1,1000,200,300,3000

During a call or ringback state, we could hear an additional beep tone mixed with the GSM ringback audio. However, it did not replace the GSM network ringback tone. It only appeared to add a generated tone on top of the existing audio.

We also tested a longer cadence such as:

AT+QLTONE=1,440,1000,2000,6000

However, this caused the call to disconnect. We later noticed that the silent interval parameter seems to be limited to 0–1000 ms, so this value may have been invalid.

Our questions are:

  1. What is the correct method to enable or use the ringing_korea.wav local ringback tone included in the EC25EFAR08A05M4G_KR firmware?

  2. Is there an AT command to select or play ringing_korea.wav directly?

  3. Is the Korean local ringback tone used only through the Voice over USB function?

  4. If so, which AT commands or configuration are required to enable Voice over USB local ringback tone playback?

  5. Is AT+QLTONE only for generating simple frequency tones, or can it be used to trigger built-in ringback tone files?

  6. Is there any way to suppress or replace the GSM network early media ringback tone with the module’s local Korean ringback tone?

  7. During outbound calls, can the module send a RINGBACK URC or similar event so that the host system can know when to start or stop local ringback playback?

  8. For failed calls such as invalid number, call rejected, or user busy, can the EC25 module provide the original network release cause through AT+CEER or another URC so that the host can distinguish these cases?

Our goal is to provide a Korean-style local ringback tone instead of the GSM network ringback tone, while still correctly detecting call answer and call failure causes.

Could you please provide the recommended AT command sequence or integration guide for using the Korean local ringback tone feature in EC25EFAR08A05M4G_KR?

Best regards,

Dear Customer,

Thank you for the thorough and well-documented report. We have gone through each of your questions carefully against the available EC2x series documentation and can provide the following responses.

Questions 1 & 2 — Using ringing_korea.wav and whether there is a direct playback command

To be straightforward on this: there is no AT command in the EC2x series that directly selects or plays an embedded audio file such as ringing_korea.wav from the AT interface. The file is part of the KR firmware variant and is not exposed as a directly addressable resource through AT commands.

The intended usage model for this file is through the Voice over USB (UAC) function. When UAC mode is enabled, the module presents itself as a USB Audio Class sound card to the host. The host application is then responsible for managing audio output — including playing the local ringback tone — through that USB audio interface at the appropriate stage of the call. In other words, ringing_korea.wav is a reference resource that the host is expected to retrieve and play locally; the module provides the audio path, not the playback trigger.

If a dedicated command does exist for direct file playback on this firmware variant, it is not documented in the currently available application notes and would need to be confirmed directly with Quectel R&D. We will flag this point for escalation — please see the end of this reply.

Questions 3 & 4 — Is the Korean ringback tone tied to Voice over USB, and how is it configured?

Yes, the local ringback tone capability described in the KR release notes is implemented through the UAC (USB Audio Class) function. The required configuration sequence is as follows:

// First, check your current USB configuration to get existing parameter values
AT+QCFG=“USBCFG”
// Note the returned values — you will need to keep all other parameters unchanged
// and only set the last parameter (UAC enable) to 1

// Enable the UAC device (only needs to be done once; survives firmware reboot)
// Replace each x with the corresponding value from the query above
AT+QCFG=“USBCFG”,0x2C7C,0x0125,x,x,x,x,x,x,1

// Reboot the module to apply the USB configuration change
AT+CFUN=1,1

// After reboot: enable PCM voice output over UAC
// Note: this setting does NOT persist across reboot — must be re-applied each power cycle
AT+QPCMV=1,2

// Place the outgoing call
ATD;


Once UAC is active, the module streams PCM audio over the USB Audio Class interface at **8 kHz sample rate, 16-bit linear, mono**. On Linux, the host application can play the ringback WAV file through the exposed sound card device using tinyalsa:

tinyplay ringing_korea.wav -D x -d 0 -c 1 -r 8000


where `x` is the sound card index assigned to the module. Please ensure the WAV file itself is encoded at 8 kHz, 16-bit, mono before playback — if the file is at a different sample rate it will need to be resampled to match the fixed PCM format the UAC interface expects.


**Question 5 — What does `AT+QLTONE` actually do, and can it play WAV files?**

`AT+QLTONE` is purely a **synthesized frequency tone generator** — it generates a single-frequency audio tone on the voice path. Looking at the parameter range you received:

+QLTONE: (0,1),(100-4000),(0-1000),(0-1000),(0-15300000)
enable freq(Hz) on(ms) off(ms) duration(ms)


It has no capability to reference or play any embedded audio file. It is suitable for generating DTMF-adjacent tones or simple alerting beeps, nothing more.

Regarding the call disconnect you observed with `AT+QLTONE=1,440,1000,2000,6000`: your own analysis is correct. The silent interval (fourth parameter) is bounded at **0–1000 ms**, so the value of 2000 ms you used is out of range. Passing an invalid parameter to a command operating on an active voice call path explains the disconnection. The command itself is not at fault — the parameter was simply invalid.


**Question 6 — Can the GSM network early media ringback tone be suppressed or replaced?**

There is no documented AT command for the EC2x series that mutes or filters network-originated early media audio selectively. In a CS call, the network may start sending early media ringback through the air interface during the alerting phase, which the module decodes and passes through the UAC PCM path to the host.

The practical way to handle this in the UAC architecture is at the **host application level**. While the call is in the alerting state, the host can play `ringing_korea.wav` locally through the UAC audio output, which is what the user hears at the speaker. Whether the host chooses to mix this with the incoming PCM stream from the network or simply override what reaches the speaker is an application-layer decision. The module itself does not provide a mechanism to block or replace network early media at the AT command level.


**Question 7 — Is there a RINGBACK URC so the host can know when to start and stop local ringback?**

There is no dedicated `+RINGBACK` URC in the EC2x series. The standard approach to detect the alerting phase for an outgoing call is through **`AT+CLCC`** polling. After issuing `ATD`, the host can poll `AT+CLCC` at short intervals — when the call status field returns `3` (mobile-originated alerting), that is the signal to start local ringback playback. When the status transitions to `0` (call active/answered), the host stops playback.

If your firmware supports **`+QIND:"callstate"`** URC, this provides the same state transitions without requiring polling. You can verify availability by sending `AT+QINDCFG=?` and checking whether `"callstate"` is listed as a configurable URC. If it is available, it is the cleaner approach. If not, polling `AT+CLCC` at 500 ms intervals during the dialing phase is a reliable fallback.


**Question 8 — Can the module report the network release cause for failed calls?**

Yes. The standard **`AT+CEER`** command returns the extended error cause code after a call ends with `NO CARRIER`. This maps to 3GPP TS 24.008 cause values and allows the host to distinguish between the failure scenarios you described:

// Issue AT+CEER immediately after receiving NO CARRIER

AT+CEER
+CEER: 1 // Unallocated or invalid number
+CEER: 17 // User busy
+CEER: 21 // Call rejected
+CEER: 34 // No circuit/channel available


One important operational note: `AT+CEER` must be queried **immediately after `NO CARRIER`** is received. Issuing any other AT command in between may clear the cached cause code, resulting in an empty or default response.