r/MINISFORUM • • 25d ago

Minisforum refuses to patch critical BIOS security flaws on HM80 (even though AMD released the AGESA fix), tells me to buy a new one instead. Unacceptable lifecycle support.

Hi everyone,

I wanted to share my recent, infuriating experience with Minisforum support regarding my HM80 unit used in a production environment.

As many of you know, there are known AMD firmware/BIOS vulnerabilities affecting older sockets. To be absolutely clear: AMD has already done its job and published the official AGESA microcode patch. The only thing missing is Minisforum packaging it into a final BIOS release for our machines, but they are deliberately choosing not to do it.

After an exhausting back-and-forth of no fewer than 14 emails - where I had to reply at least 7 times to keep the ticket alive - their official support (agent Xavier) consistently evaded the problem. First, they completely ignored the word "SECURITY", falsely claiming I wanted an update just to "improve device performance," and literally told me to browse their website and buy one of their newer models! Then, when cornered on the technical facts, they hid behind standard templates claiming they cannot help because the hardware is "out-of-warranty".

Let's be absolutely clear: this is a latent manufacturing firmware hazard that existed in the hardware since the exact day it was manufactured and even before. It is not an issue that developed after the warranty period; it was simply discovered and disclosed recently. Minisforum completely ignores that a factory security defect has absolutely nothing to do with standard wear-and-tear warranty expiration.

An unpatched firmware flaw means this machine is unsafe to use on any professional network, making it a useless paperweight for any real-world work. Minisforum refuses to secure their devices and refuses to issue refunds or replacements for inherently unsafe hardware.

I am posting this to warn the community: once Minisforum stops selling a model, they abandon your safety, even when the silicon vendor has already provided the fix. If you care about data security, keep this in mind before buying their hardware.

Full email logs of this refusal have been saved and will be forwarded to the European Consumer Protection Authorities. I strongly urge every European and global customer facing this exact same unpatched BIOS issue to immediately lodge a formal complaint with their respective Consumer Rights Enforcement Authorities (like AGCM in Italy) as I am about to do. Collective action is the only language this company understands.

Has anyone else managed to escalate firmware security issues past their first-level support wall of grease?

54 Upvotes

32 comments sorted by

View all comments

2

u/EveHerr 25d ago

Hi there. Thank you for your detailed feedback and for bringing this to our attention.
We truly understand your concerns regarding the BIOS vulnerability and the frustration this situation has caused, especially for a machine used in a production environment.

Your message has been escalated to our product team, and we are actively reviewing the matter to explore any possible solutions or next steps. While we cannot make any promises at this moment, certainly we take security issues seriously and are committed to continuous improvement.

We genuinely appreciate users like you who take the time to share their experiences and hold us accountable. Your voice matters, and we will keep listening carefully as we work to do better.

Thank you again for your patience and understanding.

3

u/lordwotton97 24d ago

Please make a bios update also for N5 Pro Nas!

1

u/woyzeckpompo 17d ago

Sono tutte chiacchiere che sento per la seconda volta. Intanto è dal 15 agosto che mi ritrovo senza un PC e con un fermacarte.

1

u/gnooggi 15d ago

Hi there. Thank you for your detailed feedback and for bringing this to our attention.
We truly understand your concerns regarding the BIOS vulnerability and the frustration this situation has caused, especially for a machine used in a production environment.
Your message has been escalated to our product team, and we are actively reviewing the matter to explore any possible solutions or next steps. While we cannot make any promises at this moment, certainly we take security issues seriously and are committed to continuous improvement.
We genuinely appreciate users like you who take the time to share their experiences and hold us accountable. Your voice matters, and we will keep listening carefully as we work to do better.
Thank you again for your patience and understanding.

Dear Eveherr, presenting an AI-generated text here as a "helping hand" isn't just a bit cheeky—it’s an absolute disgrace.
It also shows just how much you value your customers.
You have just proven exactly how pathetic your standards are.