Lenovo patches security flaw in software with '12345678' as a password

Lenovo Y50 Gaming Laptop 625x351

Earlier this week, Core Security shared an advisory calling out a severe security threat in Lenovo's ShareIt program for Windows and Android. The app, which allows you to share files between PCs and mobile devices, had a hard-coded password that is the same on every device when it sets up a Wi-Fi Hotspot to receive files. Not only that, it's a pretty terrible password too: 12345678. That's the kind of password an idiot would have on his luggage.

Thankfully, Lenovo has patched the issue, so if you're using ShareIt Android version 3.0.18_ww or Windows version 2.5.1.1, make sure it's up to date.

According to Core Security, the flaw meant that if you could connect to the Hotspot over a WiFi connection and input the simple password, you'd be able to browse the file system of the device remotely by performing an HTTP request to the WebServer. Files were also transferred via HTTP without encryption, meaning data could be viewed as it was transferred, and also allowing man in the middle attacks.

This is the second time in 12 months that Lenovo has had to fix big security flaws. In February last year, its laptops came pre-installed with the Superfish software that made the hardware vulnerable to all sorts of attacks.

Latest in Software
Otter AI Meeting Agent
As if your work meetings weren't already fun enough, now Otter has a new all-hearing AI agent that remembers everything anyone has said and can join in the discussion
Microsoft's iconic Bliss wallpaper
From pixels to pinot: The Windows XP 'Bliss' wallpaper hill was real and this is what it looks like now
Napster client circa 1999
Former music-pirating platform Napster to be reborn rather ironically as a metaverse for musicians to connect with their fans after $207 million deal
New Discord desktop client themes.
Discord drops big update with 'completely new' in-game overlay and new dark themes for the desktop client
Image for
'No real human would go four links deep into a maze of AI-generated nonsense': Cloudflare's AI Labyrinth uses decoy pages to trap web-crawling bots and feed them slop 'as a defensive weapon'
A screenshot from game Mudborne of a little humanoid frog in a marsh
Five new Steam games you probably missed (March 24, 2025)
Latest in News
An Enshrouded player in a recreation of Erebor from The Lord of the Rings
Kings under the Mountain! 33 Enshrouded players spent 10,000 hours to recreate this iconic location from The Lord of the Rings
A mech awakens.
Mecha Break developer is considering unlocking all mechs following open beta feedback
Lara Croft Unified Art
Tomb Raider developer Crystal Dynamics lays off 17 employees 'to better align our current business needs and the studio's future success'
A long bendy arm stealing money from people in a subway car
'You're a very long arm. You steal things. It's a comedy game,' explains developer of comedy game where you steal things with a very long arm
The heroes are attacked by monsters
Pillars of Eternity is getting turn-based combat to mark its 10th anniversary, and that means PC Gamer editors will soon be arguing about combat mechanics again
Image of Ronaldo from Fatal Fury: City of the Wolves trailer
It doesn't really make sense that soccer star Ronaldo is now a Fatal Fury character, but if you follow the money you can see how it happened