Junglewise Threat Intelligence

CVE-2025-13454: Lenovo ThinkPlus configuration software sensitive information disclosure

CVE-2025-13454 · Severity: medium · CVSS 5.5 · Published 2026-01-14

Vendors: Lenovo.

Executive brief

A vulnerability in Lenovo ThinkPlus configuration software could allow a person with physical or local access to a computer to view sensitive device information. This software is used to manage and configure Lenovo ThinkPlus hardware accessories. An attacker who has already gained basic access to the system could exploit this to gather technical details that might assist in further unauthorized activities.

Technical details

A vulnerability classified as Cleartext Transmission of Sensitive Information (CWE-319) exists in Lenovo ThinkPlus configuration software. The flaw allows a local authenticated user with low privileges to intercept or access sensitive device data that is not properly encrypted or protected during transmission or storage by the configuration utility. The vulnerability affects multiple ThinkPlus product lines including FU100, FU200, TSD303, and TU800. Attackers can leverage this to gain information that should be restricted to administrative or system-level access.

Affected products

  • Lenovo ThinkPlus FU100 Firmware All versions
  • Lenovo ThinkPlus FU200 Firmware All versions
  • Lenovo ThinkPlus TSD303 Firmware All versions
  • Lenovo ThinkPlus TU800 Firmware All versions

Timeline

  • 2026-01-14: disclosed: Initial disclosure by Lenovo
  • 2026-01-14: advisory: NVD publication date

References

Related threats