@Beelink CS-June
I am requesting assistance and, if available, a corrected production BIOS from your R&D team for my Beelink EQ / EQi12 system.
DEVICE INFORMATION
- Product family: Beelink EQ / EQi12
- DMI product name: EQ
- DMI board name: EQ
- System vendor: AZW
- Board vendor: AZW
- Serial number: [REDACTED! Available privately to Beelink support.]
- Processor: 13th Gen Intel Core i5-13420H
- Installed memory: 16 GB
- BIOS vendor: American Megatrends International, LLC.
- BIOS version: EQI12403
- BIOS date: 04/09/2026
- Intel Management Engine firmware: 16.1.27.2225
- Operating system: Ubuntu 24.04 ×86_64
- Kernel: 6.8.0-137-generic
- TPM: TPM 2.0
- Boot mode: UEFI
- Secure Boot: Enabled
- VT-d/IOMMU: Enabled and operational
BIOS SETTINGS ALREADY CONFIGURED
I have configured every applicable security setting exposed by the current BIOS:
- Secure Boot enabled
- UEFI-only boot enabled
- CSM disabled
- Fast Boot disabled
- TPM/PTT enabled
- VT-d enabled
- BIOS Lock enabled
- Hibernation disabled
- Legacy S3 suspend disabled
- Firmware Update enabled
- ME Firmware Image Re-Flash disabled
These changes successfully produced the following results:
- SPI writes are disabled.
- SPI lock is enabled.
- The SPI BIOS region is locked.
- UEFI boot-service variables are locked.
- Platform debugging is disabled and locked.
- IOMMU is enabled and functional.
- Secure Boot is enabled.
- TPM PCR0 reconstruction is valid.
- Legacy suspend-to-RAM is disabled.
- Linux kernel lockdown is enabled.
REMAINING FIRMWARE-LEVEL SECURITY FAILURES
The current BIOS continues to report the following failures through fwupdmgr Host Security ID validation.
HSI-1:
- BIOS firmware/capsule updates: Disabled or unsupported
- CSME manufacturing mode: Unlocked
- SPI BIOS descriptor: Invalid
- UEFI Platform Key: Invalid
HSI-2:
- Intel Boot Guard ACM protection: Invalid
- Intel Boot Guard OTP fuse configuration: Invalid
- Intel Boot Guard verified boot: Invalid
HSI-3:
- Intel Boot Guard error policy: Invalid
- Pre-boot DMA protection: Disabled
- Suspend-to-idle/S0ix: Disabled or not correctly exposed
HSI-4:
- Encrypted RAM: Not supported
SECURE BOOT PLATFORM KEY
Secure Boot is operational according to the operating system, but the firmware Platform Key is identified as invalid.
Inspection of the firmware-provided PK and PKDefault indicates that they appear to contain an expired AMI test Platform Key labeled similar to:
DO NOT TRUST - AMI Test PK
This does not appear to be a valid Beelink/AZW production Platform Key.
I have not restored the BIOS factory Secure Boot keys because I do not want to replace the currently working key configuration with expired AMI test material.
MISSING BIOS CONTROLS
The current BIOS does not expose usable settings for:
- UEFI capsule firmware updates
- Pre-boot DMA protection
- Early DMA-remapping policy
- Thunderbolt or USB4 preboot security
- Thunderbolt or USB4 PCIe-tunnelling policy
- Modern Standby or S0ix selection
- Intel Boot Guard provisioning
- CSME manufacturing-mode closure
- SPI descriptor correction
REQUEST TO THE R&D TEAM
Could you please ask the firmware or R&D team to provide or confirm the following?
A production BIOS specifically approved for this exact model, board revision, and serial-number range.
A valid production Secure Boot key set, including the Platform Key, KEK, db, and current dbx.
Support for the Microsoft UEFI CA 2023 certificate transition, where applicable.
A corrected and locked SPI flash descriptor.
CSME provisioning with manufacturing mode permanently closed.
Correct Intel Boot Guard provisioning, including ACM protection, verified-boot enforcement, OTP/fuse configuration, and a secure error policy.
Authenticated UEFI capsule firmware-update support through fwupd/LVFS or another supported mechanism.
Pre-boot DMA protection and DMA remapping before untrusted external devices can perform DMA.
Proper S0ix or Modern Standby exposure, if this hardware supports it.
Confirmation of whether the Boot Guard, CSME, and SPI descriptor findings can be repaired through a BIOS update.
If any of these findings result from immutable factory fuse or provisioning errors and cannot be corrected through firmware, please advise whether the motherboard requires replacement.
INFORMATION REQUIRED BEFORE INSTALLING A BIOS
This system uses full-disk encryption and TPM-sealed credentials. Before installing a supplied BIOS, please confirm:
- The BIOS is specifically compatible with serial number [REDACTED! Available privately to Beelink support.].
- The exact supported update procedure.
- Whether the update changes TPM PCR measurements.
- Whether the update clears or resets the TPM.
- Whether the update clears Secure Boot variables or enrolled keys.
- Whether the update restores the AMI test Platform Key.
- Whether the update resets BIOS settings.
- Whether disk-encryption recovery credentials will be required afterward.
- Whether BIOS rollback is supported.
- The safe rollback procedure, if supported.
- Whether the firmware image is production-signed.
- The expected SHA-256 digest of the firmware package.
- The BIOS version that should appear after installation.
Please do not send firmware intended only for a similar-looking model unless R&D has confirmed that it is compatible with this exact board and serial-number range.
I can provide the following privately if required:
- Complete fwupdmgr security output
- fwupdmgr security JSON evidence
- BIOS setup photographs
- Secure Boot certificate and variable information
- TPM PCR measurements
- DMI information
- Linux boot logs
- Any diagnostic package requested by your R&D team
Please let me know whether corrected firmware is already available or whether this case needs to be escalated to the firmware engineering team.
Thank you for your assistance.
Kind regards