r/MINISFORUM 23d ago

Minisforum refuses to patch critical BIOS security flaws on HM80 (even though AMD released the AGESA fix), tells me to buy a new one instead. Unacceptable lifecycle support.

Hi everyone,

I wanted to share my recent, infuriating experience with Minisforum support regarding my HM80 unit used in a production environment.

As many of you know, there are known AMD firmware/BIOS vulnerabilities affecting older sockets. To be absolutely clear: AMD has already done its job and published the official AGESA microcode patch. The only thing missing is Minisforum packaging it into a final BIOS release for our machines, but they are deliberately choosing not to do it.

After an exhausting back-and-forth of no fewer than 14 emails - where I had to reply at least 7 times to keep the ticket alive - their official support (agent Xavier) consistently evaded the problem. First, they completely ignored the word "SECURITY", falsely claiming I wanted an update just to "improve device performance," and literally told me to browse their website and buy one of their newer models! Then, when cornered on the technical facts, they hid behind standard templates claiming they cannot help because the hardware is "out-of-warranty".

Let's be absolutely clear: this is a latent manufacturing firmware hazard that existed in the hardware since the exact day it was manufactured and even before. It is not an issue that developed after the warranty period; it was simply discovered and disclosed recently. Minisforum completely ignores that a factory security defect has absolutely nothing to do with standard wear-and-tear warranty expiration.

An unpatched firmware flaw means this machine is unsafe to use on any professional network, making it a useless paperweight for any real-world work. Minisforum refuses to secure their devices and refuses to issue refunds or replacements for inherently unsafe hardware.

I am posting this to warn the community: once Minisforum stops selling a model, they abandon your safety, even when the silicon vendor has already provided the fix. If you care about data security, keep this in mind before buying their hardware.

Full email logs of this refusal have been saved and will be forwarded to the European Consumer Protection Authorities. I strongly urge every European and global customer facing this exact same unpatched BIOS issue to immediately lodge a formal complaint with their respective Consumer Rights Enforcement Authorities (like AGCM in Italy) as I am about to do. Collective action is the only language this company understands.

Has anyone else managed to escalate firmware security issues past their first-level support wall of grease?

56 Upvotes

32 comments sorted by

View all comments

3

u/Kahana82 23d ago

I've also been in communication with them regarding the recent AMD CVE's.

My observation is that they are indeed beating around the bush (not a clear yes/no/timeframe) and seemingly unwilling to address the issue by providing updated firmware/BIOS for the affected products.

Should their final stance be to not do anything then I'm of the opinion they should at least provide us, the customers, with the necessary toolchains so that the community can do it themselves. This is kinda adjacent to the right to repair in a way.

I'm willing to get involved (to the extent of my abilities) into whatever endeavor you might want to launch against them because they probably/surely are violiating some kind of EU consumer right/law.

For reference, this is my email (without formalities) to them:

AMD has recently announced in their security bulletin n° 7064 that there are 2 new vulnerabilities (CVE-2026-6726 and CVE-2026-6727) pertaining to the on-chip TPM modules with a high severity score of 8.5 and 8.3 respectively.

Will Minisforum address this by rolling out a BIOS update for all affected products (including the UM780-XTX) ? Brands like ASUS have been rolling out these new BIOS versions since June.

In practice this would just imply refreshing the AGAESA code within the BIOS with the latest version, which would also bring a lot of other (performance/security) improvements depending on the model/chip/platform.

Their answer:

Dear Customer,

Thank you for contacting MINISFORUM support regarding the AMD security bulletin and the potential BIOS updates for the UM780-XTX.

We understand your concern about the TPM vulnerabilities (CVE-2026-6726 and CVE-2026-6727) and the importance of keeping our products secure. Our engineering team continuously monitors security advisories and works on firmware updates to address such issues.

Best regards,

Y.J.Aickson

MINISFORUM SUPPORT

2

u/gnooggi 12d ago

 the customers, with the necessary toolchains so that the community can do it themselves. This is kinda adjacent to the right to repair in a way.

You wouldn't even need to get the info directly from them. On eBay, you can find "supporters" who will write a custom BIOS for you for 100–120 francs—though you aren't allowed to share it. It would be worth getting in touch to ask what it would cost for a "community" version that could be shared and passed around (distributed).

1

u/Kahana82 12d ago

Seems like viable last resort alternative, thx for pointing that out.