In one case, after they were found out they first claimed "we have thoroughly investigated this technology and do not find any evidence to substantiate security concerns" and only after it started being reported by more and more news orgs did they finally admit to what they'd done and release instructions on how to fix it.
Sadly, those instructions removed the bloatware, but left the vulnerability it introduced in place giving users a false sense of security, and only after they were caught out for that in the press did they finally release a "removal tool"
The wikipedia page doesn't even list all their offenses or the most recent events. See also : https://www.zdnet.com/article/lenovo-patches-uefi-vulnerabil...
Repairable or not, use Lenovo at your own risk.