Lenovo Tablet Auth Bypass: Obsolete Control Center Setting
CVE-2025-14058 Published on January 14, 2026

A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical access to modify Control Center settings if the device is locked when the "Allow Control Center access when locked" option is disabled.

NVD

Vulnerability Analysis

CVE-2025-14058 is exploitable with physical access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity and availability.

Attack Vector:
PHYSICAL
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
REQUIRED
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
LOW
Availability Impact:
LOW

Weakness Type

Missing Authentication for Critical Function

The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.


Products Associated with CVE-2025-14058

Want to know whenever a new CVE is published for Lenovo products? stack.watch will email you.

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Affected Versions

Lenovo Tab M11 TB330FU TB330XU: Lenovo Tab K11 TB330FU: Lenovo Tab K11 TB330FUP: Lenovo Tab K11 TB330XU: Lenovo Tab K11 TB330XUP: Lenovo Idea Tab Pro TB373FU: Lenovo Tab K9 TB305FU: Lenovo Tab K9 TB305XU: Lenovo Tab Plus TB351FU: Lenovo Tab M8 4th Gen 2024 TB301FU: Lenovo Tab M8 4th Gen 2024 TB301XU: Lenovo Tab Extreme TB570ZU TB570FU: Lenovo Tab M10 5G TB360ZU: Lenovo Tab M8 4th Gen TB300FU: Lenovo Tab M8 4th Gen TB300XU: Lenovo Tab M9 TB310FU: Lenovo Tab M9 TB310XU: Lenovo Tab P11 2nd Gen TB350XU: Lenovo Tab P11 2nd Gen TB350FU: Lenovo Tab P12 TB370FU: Lenovo Tab P12 TB372FU: Lenovo Tab K11 Plus LTE TB352FU: Lenovo Tab K11 Plus LTE TB352XU: Lenovo Yoga Tab Plus TB520FU: Lenovo Tab K11 Gen 2 TB336ZU: Lenovo TAB7: Lenovo Tab with Clear Case TB311FU: Lenovo Tab with Folio Case TB311XU: Lenovo Legion Tab TB321FU: Lenovo Legion Tab TB320FC: Lenovo Idea Tab TB336FU:

Exploit Probability

EPSS
0.04%
Percentile
10.47%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.