Minisforum accused of ignoring AMD's own BIOS security fix on a 2021 mini PC

A Reddit thread accusing Minisforum of refusing to patch a security flaw on an older mini PC is gaining traction across two subreddits. It is also drawing corroboration from other users who describe a similar pattern with the company's lineup. The claims come from scattered, unverified accounts and have not been addressed publicly by Minisforum.
According to a post by user u/woyzeckpompo, which was first published nine days ago in r/Minisforum and cross-posted to r/MiniPCs, AMD has already released an AGESA microcode update addressing firmware vulnerabilities that affect older AMD sockets. However, Minisforum has not packaged it into a BIOS release for the HM80, a mini PC built around the Ryzen 7 4800U and launched in mid-2021. The poster says they exchanged roughly 14 to 15 emails with support over several weeks, and that a representative first mischaracterized the request as a performance update, suggested buying a newer model, then said the device was out of warranty. The poster says that a firmware defect present since manufacture is unrelated to standard wear-and-tear warranty terms, and says they intend to file complaints with European consumer protection bodies, including Italy's AGCM.
Minisforum refuses to fix critical BIOS security vulnerabilities on HM80 (even though AMD released the AGESA fix), telling me to buy a new model instead. Unacceptable lifecycle support. [X-Post from r/Minisforum]
by u/woyzeckpompo in MiniPCs
Neither post names a specific CVE or vulnerability, so it isn't possible to confirm which AMD advisory is being referenced or whether it applies to the HM80's Renoir-based chip. Minisforum has not issued a public statement on the claims.
Concerned users in the thread have been communicating with other users describing similar experiences, including one who said a competing AM4 motherboard from Gigabyte still receives BIOS updates nine years after launch, and others who said the pattern can been seen with rival mini PC brands as well. Several commenters said hardware reviewers rarely mention post-sale firmware support when covering these devices.
However, the account should still be treated as a single customer's record of a support dispute rather than a confirmed disclosure.
Minisforum refuses to patch critical BIOS security flaws on HM80 (even though AMD released the AGESA fix), tells me to buy a new one instead. Unacceptable lifecycle support.
by u/woyzeckpompo in MINISFORUM
Source(s)
u/woyzeckpompo via r/MiniPCs / r/Minisforum







