CVE-2025-14058

LOW

Lenovo Tab M11 TB330FU TB330XU < 17.0.284 - Missing Authentication for Control Center Settings

Title source: llm
STIX 2.1

Description

A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical access to modify Control Center settings if the device is locked when the "Allow Control Center access when locked" option is disabled.

References (1)

Core 1

Scores

CVSS v3 3.2
EPSS 0.0004
EPSS Percentile 12.9%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (31)
Lenovo/Idea Tab Pro TB373FU < ZUI_17.0.04.266_ST_251120
Lenovo/Idea Tab TB336FU < 17.5.10.041
Lenovo/Legion Tab TB320FC < 17.0.339
Lenovo/Legion Tab TB321FU < 17.5.10.031
Lenovo/Lenovo Tab with Clear Case TB311FU < 17.0.30.303
Lenovo/Lenovo Tab with Folio Case TB311XU < 17.0.31.259
Lenovo/Tab Extreme TB570ZU TB570FU < 17.5.184
Lenovo/Tab K11 Gen 2 TB336ZU < 17.0.10.541
Lenovo/Tab K11 Plus LTE TB352FU < 17.0.10.250
Lenovo/Tab K11 Plus LTE TB352XU < 17.0.10.242
... and 21 more
Published Jan 14, 2026
Tracked Since Feb 18, 2026