CVE-2025-14058
LOWLenovo Tab M11 TB330FU TB330XU < 17.0.284 - Missing Authentication for Control Center Settings
Title source: llmDescription
A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical access to modify Control Center settings if the device is locked when the "Allow Control Center access when locked" option is disabled.
References (1)
Core 1
Core References
Various Sources
https://support.lenovo.com/us/en/product_security/LEN-207951
Scores
CVSS v3
3.2
EPSS
0.0004
EPSS Percentile
12.9%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-306
Status
published
Products (31)
Lenovo/Idea Tab Pro TB373FU
< ZUI_17.0.04.266_ST_251120
Lenovo/Idea Tab TB336FU
< 17.5.10.041
Lenovo/Legion Tab TB320FC
< 17.0.339
Lenovo/Legion Tab TB321FU
< 17.5.10.031
Lenovo/Lenovo Tab with Clear Case TB311FU
< 17.0.30.303
Lenovo/Lenovo Tab with Folio Case TB311XU
< 17.0.31.259
Lenovo/Tab Extreme TB570ZU TB570FU
< 17.5.184
Lenovo/Tab K11 Gen 2 TB336ZU
< 17.0.10.541
Lenovo/Tab K11 Plus LTE TB352FU
< 17.0.10.250
Lenovo/Tab K11 Plus LTE TB352XU
< 17.0.10.242
... and 21 more
Published
Jan 14, 2026
Tracked Since
Feb 18, 2026