A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to sensitive device information.
References
| Link | Resource |
|---|---|
| https://iknow.lenovo.com.cn/detail/436983 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
History
25 Feb 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
23 Feb 2026, 17:57
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://iknow.lenovo.com.cn/detail/436983 - Vendor Advisory | |
| First Time |
Lenovo thinkplus Tu800 Firmware
Lenovo thinkplus Fu100 Lenovo thinkplus Tsd303 Lenovo thinkplus Fu200 Firmware Lenovo thinkplus Fu200 Lenovo thinkplus Fu100 Firmware Lenovo thinkplus Tu800 Lenovo Lenovo thinkplus Tsd303 Firmware |
|
| CPE | cpe:2.3:o:lenovo:thinkplus_fu200_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkplus_tsd303_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkplus_fu200:gen1:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkplus_fu100:gen1:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkplus_fu100_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkplus_tsd303:gen1:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkplus_tu800_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkplus_tu800:gen1:*:*:*:*:*:*:* |
14 Jan 2026, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-14 23:15
Updated : 2026-02-25 22:16
NVD link : CVE-2025-13454
Mitre link : CVE-2025-13454
CVE.ORG link : CVE-2025-13454
JSON object : View
Products Affected
lenovo
- thinkplus_tsd303
- thinkplus_tu800
- thinkplus_fu100
- thinkplus_tsd303_firmware
- thinkplus_fu200
- thinkplus_fu100_firmware
- thinkplus_fu200_firmware
- thinkplus_tu800_firmware
CWE
CWE-319
Cleartext Transmission of Sensitive Information
