Lenovo
Lenovo Filez: vulnerabilities and CVEs
Lenovo Filez has 7 published vulnerabilities, 3 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs7
Last 12 months3
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2368 | High (7.5) | 0.13% | — | Mar 11, 2026 | An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code. |
| CVE-2026-1068 | Medium (6) | 0.08% | — | Mar 11, 2026 | An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application. |
| CVE-2026-0520 | Low (2.4) | 0.09% | — | Mar 11, 2026 | A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticated user to retrieve some sensitive data stored in a log file. |
| CVE-2025-6249 | High (8.4) | 0.16% | — | Jul 17, 2025 | An authentication bypass vulnerability was reported in FileZ client application that could allow a local attacker with elevated permissions access to application data. |
| CVE-2025-2070 | Medium (5.1) | 0.14% | — | Apr 25, 2025 | An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visited by a local user. |
| CVE-2025-2068 | Medium (5.1) | 0.15% | — | Apr 25, 2025 | An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user. |
| CVE-2024-8058 | High (7.6) | 0.30% | — | Dec 16, 2024 | An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ directory to read arbitrary files on the device due to URL preloading. |
Other products by Lenovo
Xclarity Administrator · 28Thinkcentre M625q Firmware · 28Ideacentre G5-14imb05 Firmware · 27Thinkcentre M75n Firmware · 27V50t-13imb Firmware · 27Ideacentre Gaming 5-14iob6 Firmware · 27Ideacentre 5-14iob6 Firmware · 27Ideacentre Creator 5-14iob6 Firmware · 26Thinkcentre M75t GEN 2 Firmware · 26V30a-22iml Firmware · 26Ideacentre C5-14imb05 Firmware · 26Ideacentre 3-07imb05 Firmware · 26