Skip to main content
EPSS 0.1%top 96%

CVE-2025-14058: CWE-306: Missing Authentication for Critical Function in Lenovo Tab M11 TB330FU TB330XU

0
Low
VulnerabilityCVE-2025-14058cvecve-2025-14058cwe-306
Published: 01/14/2026 (01/14/2026, 22:20:37 UTC)
Source: CVE Database V5
Vendor/Project: Lenovo
Product: Tab M11 TB330FU TB330XU

Description

A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical access to modify Control Center settings if the device is locked when the "Allow Control Center access when locked" option is disabled.

CVSS v4.0

Score 2.4low

Attack Vector
Physical
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
Passive
Vuln. Confidentiality
None
Vuln. Integrity
Low
Vuln. Availability
Low
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Affected software

Lenovo

Tab M11 TB330FU TB330XU

Affected versions
>=0 <17.0.284

Lenovo

Tab K11 TB330FU

Affected versions
>=0 <17.0.284

Lenovo

Tab K11 TB330FUP

Affected versions
>=0 <17.0.254

Lenovo

Tab K11 TB330XU

Affected versions
>=0 <17.0.084

Lenovo

Tab K11 TB330XUP

Affected versions
>=0 <17.0.254

Lenovo

Idea Tab Pro TB373FU

Affected versions
=0

Lenovo

Tab K9 TB305FU

Affected versions
>=0 <17.0.10.118

Lenovo

Tab K9 TB305XU

Affected versions
>=0 <17.0.10.098

Lenovo

Tab Plus TB351FU

Affected versions
>=0 <17.5.10.023

Lenovo

Tab M8 4th Gen 2024 TB301FU

Affected versions
=0

Lenovo

Tab M8 4th Gen 2024 TB301XU

Affected versions
=0

Lenovo

Tab Extreme TB570ZU TB570FU

Affected versions
>=0 <17.5.184

Lenovo

Tab M10 5G TB360ZU

Affected versions
>=0 <16.0.882

Lenovo

Tab M8 4th Gen TB300FU

Affected versions
=0

Lenovo

Tab M8 4th Gen TB300XU

Affected versions
=0

Lenovo

Tab M9 TB310FU

Affected versions
=0

Lenovo

Tab M9 TB310XU

Affected versions
=0

Lenovo

Tab P11 2nd Gen TB350XU

Affected versions
=0

Lenovo

Tab P11 2nd Gen TB350FU

Affected versions
=0

Lenovo

Tab P12 TB370FU

Affected versions
>=0 <17.0.267

Lenovo

Tab P12 TB372FU

Affected versions
>=0 <17.0.267

Lenovo

Tab K11 Plus LTE TB352FU

Affected versions
>=0 <17.0.10.250

Lenovo

Tab K11 Plus LTE TB352XU

Affected versions
>=0 <17.0.10.242

Lenovo

Yoga Tab Plus TB520FU

Affected versions
>=0 <17.5.10.036

Lenovo

Tab K11 Gen 2 TB336ZU

Affected versions
>=0 <17.0.10.541

Lenovo

TAB7

Affected versions
>=0 <17.0.10.541

Lenovo

Lenovo Tab with Clear Case TB311FU

Affected versions
>=0 <17.0.30.303

Lenovo

Lenovo Tab with Folio Case TB311XU

Affected versions
>=0 <17.0.31.259

Lenovo

Legion Tab TB321FU

Affected versions
>=0 <17.5.10.031

Lenovo

Legion Tab TB320FC

Affected versions
>=0 <17.0.339

Lenovo

Idea Tab TB336FU

Affected versions
>=0 <17.5.10.041

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 01/14/2026, 23:02:47 UTC

Technical Analysis

CVE-2025-14058 is a vulnerability classified under CWE-306 (Missing Authentication for Critical Function) found in Lenovo Tab M11 models TB330FU and TB330XU. The flaw arises when the device is locked, and the setting 'Allow Control Center access when locked' is disabled, yet an unauthorized user with physical access can still modify Control Center settings without authentication. This indicates a failure in enforcing authentication controls on critical device functions when the device is locked. The vulnerability requires physical proximity and user interaction, as the attacker must access the device physically and interact with the Control Center interface. The CVSS v4.0 score is 2.4, reflecting low severity due to limited impact and exploitation complexity. The vulnerability primarily threatens device integrity by allowing unauthorized configuration changes, which could lead to further misuse or disruption. Confidentiality is not directly impacted, and availability impact is limited. No known exploits have been reported, and no patches are currently available. The vulnerability highlights a security design oversight in Lenovo's implementation of access controls on locked devices, potentially allowing attackers to bypass intended restrictions on critical functions.

Potential Impact

For European organizations, the impact of CVE-2025-14058 is generally low but context-dependent. Organizations that deploy Lenovo Tab M11 tablets in sensitive environments where physical device access cannot be strictly controlled may face risks of unauthorized configuration changes. Such changes could facilitate further attacks or disrupt device functionality, potentially affecting operational continuity. However, since the vulnerability requires physical access and user interaction, remote exploitation is not feasible, limiting large-scale impact. Confidential data confidentiality remains intact, but integrity and availability could be marginally affected if attackers manipulate device settings. Sectors with high reliance on mobile devices for critical operations, such as government agencies, healthcare, and finance, should be particularly cautious. The absence of known exploits reduces immediate threat levels, but the vulnerability should be addressed proactively to prevent potential misuse.

Mitigation Recommendations

To mitigate CVE-2025-14058, European organizations should implement strict physical security controls to prevent unauthorized access to Lenovo Tab M11 devices, including secure storage and access policies. Administrators should verify and, if possible, disable the 'Allow Control Center access when locked' setting to ensure it is correctly enforced. Regular audits of device configurations can help detect unauthorized changes. Employing device management solutions that enforce security policies and remotely monitor device status can further reduce risk. Lenovo should be engaged to provide patches or firmware updates addressing this vulnerability; until then, organizations should limit physical access and educate users on the risks. Additionally, consider deploying endpoint security solutions that can detect anomalous configuration changes. For high-risk environments, alternative devices with stronger locked-state protections may be considered.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
lenovo
Date Reserved
2025-12-04T19:05:38.655Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 69681d11f809b25a98e646e1

Added to database: 01/14/2026, 22:47:45 UTC

Last enriched: 01/14/2026, 23:02:47 UTC

Last updated: 09/10/2026, 22:24:49 UTC

Views: 243

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses