Junglewise Threat Intelligence

CVE-2026-6281: Lenovo Personal Cloud Storage OS command injection

CVE-2026-6281 · Severity: high · CVSS 8.8 · Published 2026-05-13

Vendors: Lenovo.

Executive brief

A security vulnerability has been identified in several Lenovo Personal Cloud Storage devices, which are used by consumers to store and manage files at home. An attacker who has already gained access to the local network and has a valid user account can take full control of the device. This could lead to the theft of private data, deletion of files, or the device being used as a foothold for further attacks on the home network.

Technical details

A command injection vulnerability (CWE-78) exists in multiple Lenovo Personal Cloud Storage models, including the T1, A1, X1, T2, and A1s series. The flaw allows a remote authenticated attacker on the same local network to execute arbitrary OS commands on the device. This is caused by improper neutralization of special elements used in an OS command. While the vulnerability requires authentication, the impact is high as it allows for full system compromise. Notably, Lenovo has declared these specific models as End of Life (EOL) and has stated they will no longer receive security firmware updates, meaning no official patch is expected.

Affected products

  • Lenovo Personal Cloud Storage T1 (L-SSC201-*)
  • Lenovo Personal Cloud Storage A1 (L-SSC101/L-SSC121)
  • Lenovo Personal Cloud Storage X1 (L-SSC501-*)
  • Lenovo Personal Cloud Storage T2 (L-SSC202-*)
  • Lenovo Personal Cloud Storage A1s (L-SSC103-*)

Timeline

  • 2026-04-20: other: Lenovo issues EOL notice for affected models
  • 2026-05-13: disclosed: Vulnerability details published via NVD

References

Related threats