So I just read the article at the link you posted. It more or less confirms my suspiscion about the software.
What you want to do is probably not impossible. However, it will still take a bit of "doing". It will take some reverse engineering of the RTOS that they include as part of the isntant-on software, depending on how it's implemented, and what state the BIOS is leaving the processor and memory in when it starts to load the image from flash.
I would be curious to get my hands on a device w/ that software in it, again.
To satiate my own curiosity, though, if you don't mind, I was wondering if you could attach the output of "sudo lshw" and "sudo dmidecode" for me. I'm wondering if the flash is sitting in a standard bus that is accessible to the kernel.