Skip to content

Framework Laptop 13 11th Gen Intel® Core™ — BIOS 3.25

File Release Date
Windows BIOS v3.25 Installer 2026-07-06 Framework_Laptop_13_11th_Gen_Intel_Core_BIOS_3.25.exe SHA256 · 0DCB0A579C3F8F0D5B9848AB2EF9C5F4881765A295352B8B08D9324935E3255D
Windows Driver Bundle v3.04 2026-07-06 Framework_Laptop_13_11th_Gen_Intel_Core_driver_bundle_W11_V304_2026_06_18.exe SHA256 · BEBC431AC73CDE5470E71FA288CC9750FDB4E64A1B2EC0D525F7326B31691084
Wi-Fi Driver for use during Windows Installation 2026-06-18 Framework_W11_OOBE_Wifi_Driver_Package.zip SHA256 · 13d7286531f7fc354bf345ea6f465c76cbba79f783a44b45d4803743022b574a
EFI Shell Update (BIOS v3.25) 2026-07-06 Framework_Laptop_13_11th_Gen_Intel_Core_BIOS_3.25_EFI.zip SHA256 · 15511009EC35CF49D7ADCC16F8EC3930B0E6592DF31E93E28CEBCBC550B690B5
3.25
Released 2026-07-06
Stable
Latest
Highlights
  • Updated Intel SIC to 8063.00.
  • Updated CSME to 15.0.55.2751v6 Corporate.
  • Update Microcode to 0xBE.
  • Added support for Framework Laptop 13 Pro features - Enabled compatibility for the haptic touchpad, touch panel, and 74W battery.
  • Fixed an issue where the system was unable to boot from partially locked self-encrypting drives (SEDs)
  • Fixed an issue where the Battery Extender status was reported incorrectly following a reboot, hibernation, or shutdown after the timer had expired.
  • Enhanced the Power On AC behavior, allowing the feature to work correctly without requiring the system to boot into the Operating System at least once for initialization.
  • Secure Fix: CVE-2025-32008 - Out-of-bounds write in the firmware for the Intel(R) AMT and Intel(R) Standard Manageability within Ring 3: User Applications may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts. (CVSS 8.6)
  • Secure Fix: CVE-2025-20080 - Null pointer dereference in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability within Ring 0: Kernel may allow a denial of service. Network adversary with an unauthenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. (CVSS 6.8)
  • Secure Fix: CVE-2025-27708 - Out-of-bounds read in the firmware for some Intel(R) Converged Security and Management Engine (CSME) Firmware (FW) within Ring 0: Kernel may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. (CVSS 4.1)
  • Secure Fix: CVE-2025-31648 - Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts. (CVSS 3.9)

This BIOS update is a bundle of updates to multiple embedded components in the system. Not all of them use the same version number.

ComponentVersion
ECec_325_e12d9a6
Updated
PD3.4.0.2576
Intel CSME15.0.55.2751
Updated
Microcode0xBE
Updated
DriverVersion
Intel Chipset10.1.20398.8776
Updated
Intel GNA3.00.00.1457
Intel Management Engine2601.9.16.0
Updated
Intel Serial IO31.100.2129.8
Intel Smart Sound10.29.00.9467
Intel Sensor Solution10.29.00.9467
Intel Display32.0.101.7085
Updated
Intel Dynamic Tuning8.7.10802.26924
Realtek Audio6.0.9969.1
Updated
Realtek Audio Console1.53.393.0
Updated
Intel Thunderbolt1.41.1340.0
Intel PROSet WiFi24.30.1.1
Updated
Intel PROSet Bluetooth24.30.1.1
Updated
Goodix Fingerprint3.12804.1.290
Updated
Realtek Ethernet11013_20_07272023_08042023
SD Card Readerv4_5_10_201

You can check your current BIOS version following the steps here to determine if you are on the latest release.

Framework firmware is published to LVFS and updates via fwupd, which ships by default on most modern distributions.

Terminal window
fwupdmgr refresh --force
fwupdmgr get-updates
fwupdmgr update
  1. Download the Framework Laptop 13 11th Gen Intel® Core™ BIOS 3.25 Windows Installer.
  2. Run the .exe and click "Yes" when prompted to reboot.
  3. Wait for the firmware progress bar to complete — the system will reboot automatically. Do not interrupt.
  4. Download and install the Windows Driver Bundle v3.04 for your system if you are currently using a previous Driver Bundle release, or you are installing the Driver Bundle for the first time.
  1. Download the EFI Shell Update v3.25.
  2. Extract contents of zip folder to a FAT32 formatted USB drive. Cleanly unmount the drive before physically removing it, otherwise the BIOS update may not function correctly.
  3. Attach a charger to your device while updating.
  4. Boot your system while pressing F12 and boot from the thumb drive.
  5. Let startup.nsh run automatically.
  6. Follow the instructions to install the update.
  • The EFI update will not work with filesystems formatted using MBR
  • If you get a security violation during the EFI update, disable secure boot
  • This update requires a battery present to complete the update
  • Linux users have reported that S3 sleep no longer works

Please use the public issue tracker on GitHub to report issues.

If you experience an issue with the update that is related to your system firmware, please post as complete a description as you can, including relevant system information and external peripherals. Please note that we do not currently have a SLA for responding to issues on github, but we will be reviewing them through the bios release process, and will review them for future updates as well.

Please contact support if you have an issue regarding hardware, broken devices, returns, etc.