CVE-2025-13455: Lenovo Thinkplus FU100 Firmware

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authentication and enroll an untrusted fingerprint.

Affected products

  • Lenovo Thinkplus FU100 Firmware: affected versions not specified
  • Lenovo Thinkplus FU200 Firmware: affected versions not specified
  • Lenovo Thinkplus TSD303 Firmware: affected versions not specified
  • Lenovo Thinkplus TU800 Firmware: affected versions not specified

Published 2026-01-14. Last modified 2026-06-17.