I'm sure you know it but ill remark it: your console is xploitable, even with CN or OOT, what yet has to happen is the release of a tool. If I ever develop the skills to do it I would be a plesure to help you, but idk if this is ever going to happen ;(
Probably, but the thing is that in higher version like yours the payload neede to achieve arm9 acces is very complicated to fit in the small space the QR's give you but i'm sure its not impossible. Framebuffer adresses should be corrected also. (Maybe OOT allows more space for a proper payload?)
If I was you, I'd spam (with care) ALL gbatemp users that have a knowledge with ASM/ROP/xploits. Im sure someone will take it as a challenge and would be glad to help you.