CVE-2025-13455

A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authentication and enroll an untrusted fingerprint.
References
Link Resource
https://iknow.lenovo.com.cn/detail/436983 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:lenovo:thinkplus_fu100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkplus_fu100:gen1:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:lenovo:thinkplus_fu200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkplus_fu200:gen1:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:lenovo:thinkplus_tu800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkplus_tu800:gen1:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:lenovo:thinkplus_tsd303_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkplus_tsd303:gen1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-14 23:15

Updated : 2026-02-23 17:53


NVD link : CVE-2025-13455

Mitre link : CVE-2025-13455

CVE.ORG link : CVE-2025-13455


JSON object : View

Products Affected

lenovo

  • thinkplus_tu800_firmware
  • thinkplus_fu100
  • thinkplus_tsd303_firmware
  • thinkplus_tsd303
  • thinkplus_fu200
  • thinkplus_tu800
  • thinkplus_fu100_firmware
  • thinkplus_fu200_firmware
CWE
CWE-290

Authentication Bypass by Spoofing