CVE-2026-6281: Lenovo Home Storage Hub t20
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.
Affected products
- Lenovo Home Storage Hub t20: before 5.5.8.t20.1 (fixed in 5.5.8.t20.1)
- Lenovo Home Storage Hub x20: before 5.4.4.x20.1 (fixed in 5.4.4.x20.1)
- Lenovo Personal Cloud a1: up to and including 5.4.2.a1.3
- Lenovo Personal Cloud a1s: up to and including 5.5.6.a1s
- Lenovo Personal Cloud t1: up to and including 5.4.0.t1.6
- Lenovo Personal Cloud t2: up to and including 5.4.5.t2.2
- Lenovo Personal Cloud t2pro: before 5.4.8.t2pro.2 (fixed in 5.4.8.t2pro.2)
- Lenovo Personal Cloud t2s: before 5.5.6.t2s.3 (fixed in 5.5.6.t2s.3)
- Lenovo Personal Cloud x1: up to and including 5.4.7.x1.1
- Lenovo Personal Cloud x1s: before 5.4.8.x1s.2 (fixed in 5.4.8.x1s.2)
Published 2026-05-13. Last modified 2026-06-17.