CVE-2025-14058 - CVE House
Back to Database
Status published Low CVE-2025-14058

A potential missing authentication vulnerability was reported in some Lenovo...

Vulnerability Description

A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical access to modify Control Center settings if the device is locked when the "Allow Control Center access when locked" option is disabled.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-14058

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Lenovo thanks Pablo Vivanco of DeepSecurity for reporting this issue.

Affected Vendor

Affected Software

Tab M11 TB330FU TB330XU, Tab K11 TB330FU, Tab K11 TB330FUP, Tab K11 TB330XU, Tab K11 TB330XUP, Idea Tab Pro TB373FU, Tab K9 TB305FU, Tab K9 TB305XU, Tab Plus TB351FU, Tab M8 4th Gen 2024 TB301FU, Tab M8 4th Gen 2024 TB301XU, Tab Extreme TB570ZU TB570FU, Tab M10 5G TB360ZU, Tab M8 4th Gen TB300FU, Tab M8 4th Gen TB300XU, Tab M9 TB310FU, Tab M9 TB310XU, Tab P11 2nd Gen TB350XU, Tab P11 2nd Gen TB350FU, Tab P12 TB370FU, Tab P12 TB372FU, Tab K11 Plus LTE TB352FU, Tab K11 Plus LTE TB352XU, Yoga Tab Plus TB520FU, Tab K11 Gen 2 TB336ZU, TAB7, Lenovo Tab with Clear Case TB311FU, Lenovo Tab with Folio Case TB311XU, Legion Tab TB321FU, Legion Tab TB320FC, Idea Tab TB336FU
Vulnerable Versions:
0

Timeline

Official Publish: January 14th, 2026
Last Modified: January 15th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

Weaknesses (CWE)