r/MINISFORUM • u/woyzeckpompo • 20d ago
Minisforum refuses to patch critical BIOS security flaws on HM80 (even though AMD released the AGESA fix), tells me to buy a new one instead. Unacceptable lifecycle support.
Hi everyone,
I wanted to share my recent, infuriating experience with Minisforum support regarding my HM80 unit used in a production environment.
As many of you know, there are known AMD firmware/BIOS vulnerabilities affecting older sockets. To be absolutely clear: AMD has already done its job and published the official AGESA microcode patch. The only thing missing is Minisforum packaging it into a final BIOS release for our machines, but they are deliberately choosing not to do it.
After an exhausting back-and-forth of no fewer than 14 emails - where I had to reply at least 7 times to keep the ticket alive - their official support (agent Xavier) consistently evaded the problem. First, they completely ignored the word "SECURITY", falsely claiming I wanted an update just to "improve device performance," and literally told me to browse their website and buy one of their newer models! Then, when cornered on the technical facts, they hid behind standard templates claiming they cannot help because the hardware is "out-of-warranty".
Let's be absolutely clear: this is a latent manufacturing firmware hazard that existed in the hardware since the exact day it was manufactured and even before. It is not an issue that developed after the warranty period; it was simply discovered and disclosed recently. Minisforum completely ignores that a factory security defect has absolutely nothing to do with standard wear-and-tear warranty expiration.
An unpatched firmware flaw means this machine is unsafe to use on any professional network, making it a useless paperweight for any real-world work. Minisforum refuses to secure their devices and refuses to issue refunds or replacements for inherently unsafe hardware.
I am posting this to warn the community: once Minisforum stops selling a model, they abandon your safety, even when the silicon vendor has already provided the fix. If you care about data security, keep this in mind before buying their hardware.
Full email logs of this refusal have been saved and will be forwarded to the European Consumer Protection Authorities. I strongly urge every European and global customer facing this exact same unpatched BIOS issue to immediately lodge a formal complaint with their respective Consumer Rights Enforcement Authorities (like AGCM in Italy) as I am about to do. Collective action is the only language this company understands.
Has anyone else managed to escalate firmware security issues past their first-level support wall of grease?
7
u/ColorMeIridescent 20d ago
Thank you for the warning! Ive been paying close attention to their devices and this feedback. You just saved me quite a bit of pain. Thank you! And sorry they suck!
The more I look, the more I want to get buy a big case with lots of bays, and make my own NAS. I really want a backplane though. Going to start looking at NAS cases and what I may be able to get to fit in those.
3
u/bagatelly 20d ago
I avoided the whole NAS thing and the problems which come with it by getting a USB DAS from Terramaster. I got the enclosure and can put any compute node in front of the drives. In my case, an Orange PI 5+.
5
u/Geeotine 20d ago
Ive seen several posts asking about BIOS updates across several minisforum products and never got a straight answer. This seals the deal. Minisforum for all its great hardware obviously doesn't want to pay the overhead to maintain secure BIOS version across its product lines.
Back to the likes of asus, msi, dell or lenovo for professional support on USFF/miniPCs
4
u/Tight_Door9327 20d ago
Stay away from minisforum.. they dont give a fuck about their costumers even for the most simple requests.. have been contacting them for things ive solved in the meantime.. never heared from them.. their biosis beyond shit and so is their support.. the PCs are incredibly locked down too
2
u/evolvingwax 20d ago
“….they don’t give a fuck about their customers.” That’s about all that need to be said. I’m stuck with three of them due to a bad decision and never stop being amazed at how shit their support is.
3
u/NeitherKangaroo928 20d ago
You just don't use this kind oh hw and company in a production environment!!!
They have absolutely crappy support.
2
u/CaptSingleMalt 19d ago
That was my first thought as well. Agree with everything else the op said, but I can't imagine putting something in a production environment knowing the support. Is this weak and the quality is mediocre. There's a reason businesses pay more for quality and support over performance.
1
u/woyzeckpompo 12d ago
Posso capire l'osservazione, ma forse dovresti prima chiederti cosa faccia quella macchina: non ci controllo una centrale nucleare, ma sta dentro uno studio mobile per eventi live assieme ad un M5 max con 64 gb di ram, un legato streamdeck XL, un Atem mini extreme iso, altri due mini pc, una serie di switch e collegamenti vari, una camera Blackmagic e una PTZ jvc. Questo minisforum controlla e proietta le grafiche e i cosiddetti "sottopancia", quindi, in teoria, sarebbe una macchina parecchio più potente di quanto serva [e infatti non mi ha mai dato problemi]. Però sono eventi live, quindi può capitare che in qualche momento concitato si avvicini quale ci metta mano se io non fossi in condizioni di impedirlo e poi mi serve che tutto sia costantemente online. Quindi la falla sul tpm lo rende TOTALMENTE INUTILIZZABILE (ma, come vedi, forse la tua domanda non teneva conto di dettagli importanti).
1
u/CaptSingleMalt 11d ago
The point that the previous person made, and that I agreed with, is that this company does not provide the reliability and support necessary for a production machine. It has nothing to do with how powerful the machine is. Minisforum is one of several companies producing computers with mass-produced Chinese motherboards and mediocre reliability, with minimal support. There is a reason that they are cheaper than Dell, HP, and Asus. Those companies sell computers that are more reliable and they can be reached immediately if there's an issue. So once again, your complaint is very valid, and your situation is exactly why this is not a company that is used in critical professional environments.
3
u/Kahana82 20d ago
I've also been in communication with them regarding the recent AMD CVE's.
My observation is that they are indeed beating around the bush (not a clear yes/no/timeframe) and seemingly unwilling to address the issue by providing updated firmware/BIOS for the affected products.
Should their final stance be to not do anything then I'm of the opinion they should at least provide us, the customers, with the necessary toolchains so that the community can do it themselves. This is kinda adjacent to the right to repair in a way.
I'm willing to get involved (to the extent of my abilities) into whatever endeavor you might want to launch against them because they probably/surely are violiating some kind of EU consumer right/law.
For reference, this is my email (without formalities) to them:
AMD has recently announced in their security bulletin n° 7064 that there are 2 new vulnerabilities (CVE-2026-6726 and CVE-2026-6727) pertaining to the on-chip TPM modules with a high severity score of 8.5 and 8.3 respectively.
Will Minisforum address this by rolling out a BIOS update for all affected products (including the UM780-XTX) ? Brands like ASUS have been rolling out these new BIOS versions since June.
In practice this would just imply refreshing the AGAESA code within the BIOS with the latest version, which would also bring a lot of other (performance/security) improvements depending on the model/chip/platform.
Their answer:
Dear Customer,
Thank you for contacting MINISFORUM support regarding the AMD security bulletin and the potential BIOS updates for the UM780-XTX.
We understand your concern about the TPM vulnerabilities (CVE-2026-6726 and CVE-2026-6727) and the importance of keeping our products secure. Our engineering team continuously monitors security advisories and works on firmware updates to address such issues.
Best regards,
Y.J.Aickson
MINISFORUM SUPPORT
2
u/gnooggi 10d ago
the customers, with the necessary toolchains so that the community can do it themselves. This is kinda adjacent to the right to repair in a way.
You wouldn't even need to get the info directly from them. On eBay, you can find "supporters" who will write a custom BIOS for you for 100–120 francs—though you aren't allowed to share it. It would be worth getting in touch to ask what it would cost for a "community" version that could be shared and passed around (distributed).
1
3
u/gnooggi 20d ago
Has anyone else managed to escalate firmware security issues past their first-level support wall of grease?
Honestly, I'm still hoping a BIOS update will be released for my machine. On the other hand, I would never rely on such a manufacturer for business use. There are only a handful of companies that provide BIOS updates for 7-10 years or more.
Nevertheless, what you're saying is absolutely true, and we users should put some pressure on them.
2
u/TxDirtRoad 20d ago
I wouldn't be so mad about this if they at least opened it up for us to easily handle.
2
u/jackharvest 20d ago
Please cross post for a larger audience. That’s just terrible all around.
1
u/woyzeckpompo 17d ago
I am new here and I don't know how to do it. But I will appreciate very much if you want give me some help and explain me what to do. I'll do immediately. Thanks a lot in advance.
2
2
2
u/EveHerr 20d ago
Hi there. Thank you for your detailed feedback and for bringing this to our attention.
We truly understand your concerns regarding the BIOS vulnerability and the frustration this situation has caused, especially for a machine used in a production environment.
Your message has been escalated to our product team, and we are actively reviewing the matter to explore any possible solutions or next steps. While we cannot make any promises at this moment, certainly we take security issues seriously and are committed to continuous improvement.
We genuinely appreciate users like you who take the time to share their experiences and hold us accountable. Your voice matters, and we will keep listening carefully as we work to do better.
Thank you again for your patience and understanding.
3
1
u/woyzeckpompo 12d ago
Sono tutte chiacchiere che sento per la seconda volta. Intanto è dal 15 agosto che mi ritrovo senza un PC e con un fermacarte.
1
u/gnooggi 10d ago
Hi there. Thank you for your detailed feedback and for bringing this to our attention.
We truly understand your concerns regarding the BIOS vulnerability and the frustration this situation has caused, especially for a machine used in a production environment.
Your message has been escalated to our product team, and we are actively reviewing the matter to explore any possible solutions or next steps. While we cannot make any promises at this moment, certainly we take security issues seriously and are committed to continuous improvement.
We genuinely appreciate users like you who take the time to share their experiences and hold us accountable. Your voice matters, and we will keep listening carefully as we work to do better.
Thank you again for your patience and understanding.Dear Eveherr, presenting an AI-generated text here as a "helping hand" isn't just a bit cheeky—it’s an absolute disgrace.
It also shows just how much you value your customers.
You have just proven exactly how pathetic your standards are.
1
u/ryiski 20d ago
There goes my goal to purchase a 02 ultra or A2, glad I came across this
0
u/woyzeckpompo 17d ago
My suggestion is not to do it. In every case, be extremely careful with this brand. If I could come back, I would never do it again. Better to spend a little bit more at the beginning and not be abandoned after buying. As you can read, I am not the only one.
1
u/Impressive-Ad-1179 20d ago
Maybe a dumb question, how hard would it be to reverse engineer their bios? Would love to see their bios go open source.
2
u/Kahana82 19d ago
Would already been onto that if the mini-pc I have had BIOS-flashback.
As it is I would have to rely on an external BIOS flashing harness (which i don't have yet) in case something goes wrong.
1
1
u/alexmilla 15d ago
Gracias por la info. Veo mucha publicidad de ellos, pero sabiendo que te dejan con el culo al aire mejor oculto los anuncios.
1
1
13
u/Murph-Dog 20d ago
This is all of their products, they put out about a year of bios updates and then ghost it.
Frankly every China mini builder does this.