CVE-2025-13455 Details
Description
A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authentication and enroll an untrusted fingerprint.
A vulnerability in ThinkPlus configuration software could enable a local authenticated user to bypass device authentication and enroll an untrusted fingerprint. This issue affects several ThinkPlus USB drives, including the FU100, FU200, TU800, and TSD303 models.
Lenovo has released a hardware-level solution for this vulnerability. Affected users can request a free after-sales upgrade by calling +86 400-640-1886. It is recommended to back up important data and thoroughly delete or format the device before sending it for the upgrade.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://iknow.lenovo.com.cn/detail/436983 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lenovo thinkplus fu100 firmware | All versions |
CPE
Remediation
| |
| lenovo thinkplus fu100 | gen1 |
CPE
Remediation
| |
| lenovo thinkplus fu200 firmware | All versions |
CPE
Remediation
| |
| lenovo thinkplus fu200 | gen1 |
CPE
Remediation
| |
| lenovo thinkplus tu800 firmware | All versions |
CPE
Remediation
| |
| lenovo thinkplus tu800 | gen1 |
CPE
Remediation
| |
| lenovo thinkplus tsd303 firmware | All versions |
CPE
Remediation
| |
| lenovo thinkplus tsd303 | gen1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 23, 2026 | Initial Analysis | [email protected] |
| Jan 14, 2026 | New CVE Received | [email protected] |