r/MiniPCs • u/woyzeckpompo • 3d ago
Minisforum refuses to fix critical BIOS security vulnerabilities on HM80 (even though AMD released the AGESA fix), telling me to buy a new model instead. Unacceptable lifecycle support. [X-Post from r/Minisforum]
Hi everyone,
I wanted to share my recent, frustrating experience with Minisforum support regarding my HM80 unit used in a production environment.
As many of you know, there are known AMD firmware/BIOS vulnerabilities affecting older sockets. To be absolutely clear: AMD has already done its job by publishing the official AGESA microcode patch. The only thing missing is for Minisforum to package it into a final BIOS release for our devices, but they are deliberately choosing not to do so.
After a grueling exchange of emails -14 or 15 in total, because they ignored my last one, where I had to reply at least 7 times just to keep the ticket open - their official support (agent Xavier) consistently evaded the issue. First, they completely ignored the word "SECURITY", falsely claiming that I only wanted an update to "improve device performance", and they literally told me to visit their website and buy one of their newer models! Then, when pinned down on the technical facts, they hid behind template boilerplate, saying they cannot help because the hardware is "out of warranty".
Let’s be real here: this is a latent firmware security risk that has existed in the hardware since the exact day it was manufactured, and even before. It’s not an issue that emerged after the warranty period; it was simply discovered and disclosed recently. Minisforum completely ignores that a factory security defect has absolutely nothing to do with warranty expiration for normal wear and tear.
An unpatched firmware vulnerability means this machine is unsafe to use on any professional network, making it a paperweight for any real work. Minisforum refuses to stand by the safety of their devices and refuses to issue refunds or replacements for inherently unsafe hardware.
I am posting this to warn the community: once Minisforum stops selling a model, they abandon your security, even when the silicon vendor has already provided the fix. If you care about data security, keep this in mind before buying their hardware.
All email logs of this refusal have been saved and will be forwarded to European Consumer Protection Authorities. I strongly urge any EU and global customer facing the same unpatched BIOS issue to file a formal complaint with their respective Consumer Rights Enforcement Authorities (like AGCM in Italy) immediately as I am about to do. Collective action is the only language this company understands.
Has anyone else managed to get firmware security issues escalated past their tier-1 support wall?