Executive brief
A security vulnerability has been identified in several models of Lenovo ThinkPlus USB drives, which are portable storage devices used for data transfer and backup. If an unauthorized person gains physical possession of the drive, they may be able to bypass security measures to read the sensitive files stored on it. This could lead to the exposure of confidential personal or corporate information if a drive is lost or stolen.
Technical details
A vulnerability classified as Missing Encryption of Sensitive Data (CWE-311) exists in the firmware of several Lenovo ThinkPlus USB drive models, including the FU100, FU200, TSD303, and TU800. The flaw allows an attacker with physical access to the hardware to bypass intended access controls and read the raw data stored on the drive. The attack vector is strictly physical, requiring no prior authentication or user interaction. Successful exploitation results in a total loss of confidentiality for the data residing on the affected storage media. Users are advised to refer to Lenovo's advisory for potential firmware updates or mitigation strategies.
Affected products
- Lenovo ThinkPlus FU100 Gen 1
- Lenovo ThinkPlus FU200 Gen 1
- Lenovo ThinkPlus TSD303 Gen 1
- Lenovo ThinkPlus TU800 Gen 1
Timeline
- 2026-01-14: disclosed: Initial disclosure by Lenovo
- 2026-01-14: advisory: NVD publication date