CVE-2025-13714
7.8Tencent · MedicalNet
Tencent MedicalNet contains a deserialization vulnerability in the generate_model function, allowing remote attackers to execute arbitrary code with root privileges.
Executive summary
A critical deserialization vulnerability in Tencent MedicalNet allows unauthenticated remote attackers to execute arbitrary code with root-level privileges by tricking a user into interacting with malicious content.
Vulnerability
The flaw exists within the generate_model function due to improper validation of user-supplied data, leading to the deserialization of untrusted data. An attacker can exploit this by enticing a user to open a malicious file or visit a malicious page, resulting in remote code execution under the context of the root user.
Business impact
The potential for root-level remote code execution poses a severe risk to organizational security, as it grants an attacker complete control over the compromised system. With a CVSS score of 7.8, this vulnerability represents a high-severity threat that could lead to total data compromise, unauthorized system manipulation, and lateral movement within the network. Immediate mitigation is required to prevent catastrophic loss of confidentiality, integrity, and availability.
Remediation
Immediate Action: Review the upstream fix commit (1679f7ced8fd3e9ce1acc3b86cd840b5abdaa836) and apply the corresponding security update to your MedicalNet installation.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or abnormal file access attempts originating from the MedicalNet service.
Compensating Controls: Implement strict egress filtering and ensure that the application is running with the least privilege necessary, even if the service requires root for specific operations.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for root-level code execution, this vulnerability demands prompt attention. Administrators should prioritize identifying instances of the affected version and applying the vendor-supplied fix as soon as possible to neutralize the risk of unauthorized system takeover.
More Tencent CVEs
Sources
- ZDI-25-1031
- vendor-provided URL Vendor advisory