CVE-2026-6281: Lenovo Home Storage Hub t20

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.

Affected products

  • Lenovo Home Storage Hub t20: before 5.5.8.t20.1 (fixed in 5.5.8.t20.1)
  • Lenovo Home Storage Hub x20: before 5.4.4.x20.1 (fixed in 5.4.4.x20.1)
  • Lenovo Personal Cloud a1: up to and including 5.4.2.a1.3
  • Lenovo Personal Cloud a1s: up to and including 5.5.6.a1s
  • Lenovo Personal Cloud t1: up to and including 5.4.0.t1.6
  • Lenovo Personal Cloud t2: up to and including 5.4.5.t2.2
  • Lenovo Personal Cloud t2pro: before 5.4.8.t2pro.2 (fixed in 5.4.8.t2pro.2)
  • Lenovo Personal Cloud t2s: before 5.5.6.t2s.3 (fixed in 5.5.6.t2s.3)
  • Lenovo Personal Cloud x1: up to and including 5.4.7.x1.1
  • Lenovo Personal Cloud x1s: before 5.4.8.x1s.2 (fixed in 5.4.8.x1s.2)

Published 2026-05-13. Last modified 2026-06-17.