CVE-2025-13710
7.8Tencent · HunyuanVideo
A deserialization vulnerability in the Tencent HunyuanVideo load_vae function allows remote attackers to execute arbitrary code with root privileges via malicious file or page interaction.
Executive summary
A critical deserialization vulnerability in Tencent HunyuanVideo could allow an unauthenticated attacker to achieve remote code execution with root-level privileges.
Vulnerability
The vulnerability exists within the load_vae function due to improper validation of user-supplied data, leading to the deserialization of untrusted data. This flaw allows an attacker to execute arbitrary code as root if a user is coerced into opening a malicious file or visiting a compromised webpage.
Business impact
The potential for remote code execution with root privileges poses a severe risk to the confidentiality, integrity, and availability of the affected system. Successful exploitation could lead to full system compromise, unauthorized data access, and potential lateral movement within the network. Given the CVSS score of 7.8, this vulnerability represents a high-severity threat that requires immediate attention to prevent significant operational and security impact.
Remediation
Immediate Action: Apply the vendor-provided patch immediately by integrating the fix commit b47e10b95483aa8458b64d23350844c29e91c408 into your deployment.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected file access requests originating from the HunyuanVideo component.
Compensating Controls: Implement strict file validation and restrict the execution environment of the HunyuanVideo service to a non-privileged user account to limit the impact of potential code execution.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Tencent HunyuanVideo users must treat this vulnerability with high priority. Organizations should prioritize the application of the available source code patch to eliminate the deserialization risk. Until the patch is applied, users should exercise caution regarding untrusted files or links processed by this software to prevent triggering the exploit.
More Tencent CVEs
Sources
- ZDI-25-1030
- vendor-provided URL Vendor advisory