CVE-2025-13453: Lenovo Thinkplus FU100 Firmware

Medium severity, CVSS 4.6. EPSS: 0.1% chance of exploitation in the next 30 days.

A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the drive.

Affected products

  • Lenovo Thinkplus FU100 Firmware: affected versions not specified
  • Lenovo Thinkplus FU200 Firmware: affected versions not specified
  • Lenovo Thinkplus TSD303 Firmware: affected versions not specified
  • Lenovo Thinkplus TU800 Firmware: affected versions not specified

Published 2026-01-14. Last modified 2026-06-17.