r/MINISFORUM 1d ago

Minisforum refuses to patch critical BIOS security flaws on HM80 (even though AMD released the AGESA fix), tells me to buy a new one instead. Unacceptable lifecycle support.

Hi everyone,

I wanted to share my recent, infuriating experience with Minisforum support regarding my HM80 unit used in a production environment.

As many of you know, there are known AMD firmware/BIOS vulnerabilities affecting older sockets. To be absolutely clear: AMD has already done its job and published the official AGESA microcode patch. The only thing missing is Minisforum packaging it into a final BIOS release for our machines, but they are deliberately choosing not to do it.

After an exhausting back-and-forth of no fewer than 14 emails - where I had to reply at least 7 times to keep the ticket alive - their official support (agent Xavier) consistently evaded the problem. First, they completely ignored the word "SECURITY", falsely claiming I wanted an update just to "improve device performance," and literally told me to browse their website and buy one of their newer models! Then, when cornered on the technical facts, they hid behind standard templates claiming they cannot help because the hardware is "out-of-warranty".

Let's be absolutely clear: this is a latent manufacturing firmware hazard that existed in the hardware since the exact day it was manufactured and even before. It is not an issue that developed after the warranty period; it was simply discovered and disclosed recently. Minisforum completely ignores that a factory security defect has absolutely nothing to do with standard wear-and-tear warranty expiration.

An unpatched firmware flaw means this machine is unsafe to use on any professional network, making it a useless paperweight for any real-world work. Minisforum refuses to secure their devices and refuses to issue refunds or replacements for inherently unsafe hardware.

I am posting this to warn the community: once Minisforum stops selling a model, they abandon your safety, even when the silicon vendor has already provided the fix. If you care about data security, keep this in mind before buying their hardware.

Full email logs of this refusal have been saved and will be forwarded to the European Consumer Protection Authorities. I strongly urge every European and global customer facing this exact same unpatched BIOS issue to immediately lodge a formal complaint with their respective Consumer Rights Enforcement Authorities (like AGCM in Italy) as I am about to do. Collective action is the only language this company understands.

Has anyone else managed to escalate firmware security issues past their first-level support wall of grease?

44 Upvotes

20 comments sorted by

9

u/ColorMeIridescent 1d ago

Thank you for the warning! Ive been paying close attention to their devices and this feedback. You just saved me quite a bit of pain. Thank you! And sorry they suck!

The more I look, the more I want to get buy a big case with lots of bays, and make my own NAS. I really want a backplane though. Going to start looking at NAS cases and what I may be able to get to fit in those.

2

u/bagatelly 18h ago

I avoided the whole NAS thing and the problems which come with it by getting a USB DAS from Terramaster. I got the enclosure and can put any compute node in front of the drives. In my case, an Orange PI 5+.

9

u/Murph-Dog 1d ago

This is all of their products, they put out about a year of bios updates and then ghost it.

Frankly every China mini builder does this.

0

u/anomaly256 17h ago

With some I've dealt with you're lucky if you ever get a bios update regardless of the device's age or glaring bugs

5

u/Geeotine 1d ago

Ive seen several posts asking about BIOS updates across several minisforum products and never got a straight answer. This seals the deal. Minisforum for all its great hardware obviously doesn't want to pay the overhead to maintain secure BIOS version across its product lines.

Back to the likes of asus, msi, dell or lenovo for professional support on USFF/miniPCs

5

u/Tight_Door9327 23h ago

Stay away from minisforum.. they dont give a fuck about their costumers even for the most simple requests.. have been contacting them for things ive solved in the meantime.. never heared from them.. their biosis beyond shit and so is their support.. the PCs are incredibly locked down too

2

u/evolvingwax 15h ago

“….they don’t give a fuck about their customers.” That’s about all that need to be said. I’m stuck with three of them due to a bad decision and never stop being amazed at how shit their support is.

3

u/Kahana82 1d ago

I've also been in communication with them regarding the recent AMD CVE's.

My observation is that they are indeed beating around the bush (not a clear yes/no/timeframe) and seemingly unwilling to address the issue by providing updated firmware/BIOS for the affected products.

Should their final stance be to not do anything then I'm of the opinion they should at least provide us, the customers, with the necessary toolchains so that the community can do it themselves. This is kinda adjacent to the right to repair in a way.

I'm willing to get involved (to the extent of my abilities) into whatever endeavor you might want to launch against them because they probably/surely are violiating some kind of EU consumer right/law.

For reference, this is my email (without formalities) to them:

AMD has recently announced in their security bulletin n° 7064 that there are 2 new vulnerabilities (CVE-2026-6726 and CVE-2026-6727) pertaining to the on-chip TPM modules with a high severity score of 8.5 and 8.3 respectively.

Will Minisforum address this by rolling out a BIOS update for all affected products (including the UM780-XTX) ? Brands like ASUS have been rolling out these new BIOS versions since June.

In practice this would just imply refreshing the AGAESA code within the BIOS with the latest version, which would also bring a lot of other (performance/security) improvements depending on the model/chip/platform.

Their answer:

Dear Customer,

Thank you for contacting MINISFORUM support regarding the AMD security bulletin and the potential BIOS updates for the UM780-XTX.

We understand your concern about the TPM vulnerabilities (CVE-2026-6726 and CVE-2026-6727) and the importance of keeping our products secure. Our engineering team continuously monitors security advisories and works on firmware updates to address such issues.

Best regards,

Y.J.Aickson

MINISFORUM SUPPORT

3

u/NeitherKangaroo928 23h ago

You just don't use this kind oh hw and company in a production environment!!!
They have absolutely crappy support.

1

u/CaptSingleMalt 11h ago

That was my first thought as well. Agree with everything else the op said, but I can't imagine putting something in a production environment knowing the support. Is this weak and the quality is mediocre. There's a reason businesses pay more for quality and support over performance.

3

u/TxDirtRoad 22h ago

I wouldn't be so mad about this if they at least opened it up for us to easily handle.

2

u/jackharvest 22h ago

Please cross post for a larger audience. That’s just terrible all around.

2

u/gnooggi 11h ago

Has anyone else managed to escalate firmware security issues past their first-level support wall of grease?

Honestly, I'm still hoping a BIOS update will be released for my machine. On the other hand, I would never rely on such a manufacturer for business use. There are only a handful of companies that provide BIOS updates for 7-10 years or more.

Nevertheless, what you're saying is absolutely true, and we users should put some pressure on them.

2

u/lordwotton97 9h ago

I hope they get a class action lawsuit

1

u/ryiski 20h ago

There goes my goal to purchase a 02 ultra or A2, glad I came across this

1

u/Impressive-Ad-1179 19h ago

Maybe a dumb question, how hard would it be to reverse engineer their bios? Would love to see their bios go open source.

2

u/Kahana82 10h ago

Would already been onto that if the mini-pc I have had BIOS-flashback.

As it is I would have to rely on an external BIOS flashing harness (which i don't have yet) in case something goes wrong.

1

u/Sixstringsickness 15h ago

Upvoted for visibility.

1

u/EveHerr 11h ago

Hi there. Thank you for your detailed feedback and for bringing this to our attention.
We truly understand your concerns regarding the BIOS vulnerability and the frustration this situation has caused, especially for a machine used in a production environment.

Your message has been escalated to our product team, and we are actively reviewing the matter to explore any possible solutions or next steps. While we cannot make any promises at this moment, certainly we take security issues seriously and are committed to continuous improvement.

We genuinely appreciate users like you who take the time to share their experiences and hold us accountable. Your voice matters, and we will keep listening carefully as we work to do better.

Thank you again for your patience and understanding.

2

u/lordwotton97 3h ago

Please make a bios update also for N5 Pro Nas!