CVE-2025-13713
7.8Tencent · Hunyuan3D-1
A deserialization vulnerability in the load_pretrained function of Tencent Hunyuan3D-1 allows for remote code execution when a user interacts with a malicious file or page.
Executive summary
A critical deserialization flaw in Tencent Hunyuan3D-1 enables remote code execution with root privileges, posing a severe risk to system integrity.
Vulnerability
The vulnerability exists within the load_pretrained function due to insufficient validation of user-supplied data. This allows an attacker to perform deserialization of untrusted data, resulting in code execution with root-level privileges upon successful user interaction.
Business impact
The ability for an unauthenticated attacker to execute code as root represents a total compromise of the affected host. Given the CVSS score of 7.8, this vulnerability carries significant risk for data exfiltration, permanent system damage, or lateral movement within the network. Immediate remediation is required to prevent unauthorized access and potential catastrophic system failure.
Remediation
Immediate Action: Apply the vendor-provided fix by implementing the commit 454284503670312d4e06f6251c9be2f9f6d0fae7 or updating to the latest stable version of the software.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected file system modifications originating from the Hunyuan3D-1 application.
Compensating Controls: Restrict access to the application to trusted users only and implement strict egress filtering to prevent the application from communicating with unauthorized external domains.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability presents a significant security risk due to the potential for root-level code execution. Administrators should verify their current version against the affected commit hash and apply the available patch immediately. Do not delay, as deserialization vulnerabilities are frequently targeted by threat actors to establish persistence on vulnerable infrastructure.
More Tencent CVEs
Sources
- ZDI-25-1027
- vendor-provided URL Vendor advisory