CVE-2025-13455
A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authentication and enroll an untrusted fingerprint.
Published:Jan 14, 2026
Last Modified:Feb 23, 2026
EPS:Jan 14, 2026
EPSS Score:0.0002
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Lenovo
Product
Thinkplus Fu100
Lenovo
Thinkplus Fu100
Vendor
Lenovo
Product
Thinkplus Fu100 Firmware
Lenovo
Thinkplus Fu100 Firmware
Vendor
Lenovo
Product
Thinkplus Fu200
Lenovo
Thinkplus Fu200
Vendor
Lenovo
Product
Thinkplus Fu200 Firmware
Lenovo
Thinkplus Fu200 Firmware
Vendor
Lenovo
Product
Thinkplus Tsd303
Lenovo
Thinkplus Tsd303
Vendor
Lenovo
Product
Thinkplus Tsd303 Firmware
Lenovo
Thinkplus Tsd303 Firmware
Vendor
Lenovo
Product
Thinkplus Tu800
Lenovo
Thinkplus Tu800
Vendor
Lenovo
Product
Thinkplus Tu800 Firmware
Lenovo
Thinkplus Tu800 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
