CVE-2025-14058: Lenovo Idea Tab Pro TB373FU
Low severity, CVSS 3.2. EPSS: 0.2% chance of exploitation in the next 30 days.
A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical access to modify Control Center settings if the device is locked when the "Allow Control Center access when locked" option is disabled.
Affected products
- Lenovo Idea Tab Pro TB373FU
- Lenovo Idea Tab TB336FU: before 17.5.10.041 (fixed in 17.5.10.041)
- Lenovo Legion Tab TB320FC: before 17.0.339 (fixed in 17.0.339)
- Lenovo Legion Tab TB321FU: before 17.5.10.031 (fixed in 17.5.10.031)
- Lenovo Lenovo Tab With Clear Case TB311FU: before 17.0.30.303 (fixed in 17.0.30.303)
- Lenovo Lenovo Tab With Folio Case TB311XU: before 17.0.31.259 (fixed in 17.0.31.259)
- Lenovo TAB7: before 17.0.10.541 (fixed in 17.0.10.541)
- Lenovo Tab Extreme TB570ZU TB570FU: before 17.5.184 (fixed in 17.5.184)
- Lenovo Tab k11 Gen 2 TB336ZU: before 17.0.10.541 (fixed in 17.0.10.541)
- Lenovo Tab k11 Plus Lte TB352FU: before 17.0.10.250 (fixed in 17.0.10.250)
- Lenovo Tab k11 Plus Lte TB352XU: before 17.0.10.242 (fixed in 17.0.10.242)
- Lenovo Tab k11 TB330FU: before 17.0.284 (fixed in 17.0.284)
- Lenovo Tab k11 TB330FUP: before 17.0.254 (fixed in 17.0.254)
- Lenovo Tab k11 TB330XU: before 17.0.084 (fixed in 17.0.084)
- Lenovo Tab k11 TB330XUP: before 17.0.254 (fixed in 17.0.254)
- Lenovo Tab k9 TB305FU: before 17.0.10.118 (fixed in 17.0.10.118)
- Lenovo Tab k9 TB305XU: before 17.0.10.098 (fixed in 17.0.10.098)
- Lenovo Tab m10 5g TB360ZU: before 16.0.882 (fixed in 16.0.882)
- Lenovo Tab m11 TB330FU TB330XU: before 17.0.284 (fixed in 17.0.284)
- Lenovo Tab m8 4th Gen 2024 TB301FU
- Lenovo Tab m8 4th Gen 2024 TB301XU
- Lenovo Tab m8 4th Gen TB300FU
- Lenovo Tab m8 4th Gen TB300XU
- Lenovo Tab m9 TB310FU
- Lenovo Tab m9 TB310XU
- and 6 more
Published 2026-01-14. Last modified 2026-06-17.