PT-2026-40698 · Lenovo · Home Storage Hub T20+9

Published

2026-05-13

·

Updated

2026-05-13

·

CVE-2026-6281

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-6281

Affected Products

Home Storage Hub T20
Home Storage Hub X20
Personal Cloud A1
Personal Cloud A1S
Personal Cloud T1
Personal Cloud T2
Personal Cloud T2Pro
Personal Cloud T2S
Personal Cloud X1
Personal Cloud X1S