CVE-2025-14058
Severity CVSS v4.0:
LOW
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
14/01/2026
Last modified:
14/01/2026
Description
A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical access to modify Control Center settings if the device is locked when the "Allow Control Center access when locked" option is disabled.
Impact
Base Score 4.0
2.40
Severity 4.0
LOW
Base Score 3.x
3.20
Severity 3.x
LOW



