CVE-2025-13715
7.8Tencent · FaceDetection-DSFD
Tencent FaceDetection-DSFD is vulnerable to remote code execution via deserialization of untrusted data in the resnet endpoint, requiring user interaction to trigger the exploit.
Executive summary
A critical deserialization vulnerability in Tencent FaceDetection-DSFD allows remote attackers to execute arbitrary code with root privileges if a user is tricked into interacting with malicious content.
Vulnerability
The flaw resides in the resnet endpoint and stems from improper validation of user-supplied data, leading to the deserialization of untrusted data. The attack vector is local (AV:L), though it requires user interaction to facilitate the execution of arbitrary code in the context of the root user.
Business impact
Successful exploitation of this vulnerability grants an attacker full control over the affected system by executing code with root privileges. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to complete system compromise, data exfiltration, or the installation of persistent malicious backdoors.
Remediation
Immediate Action: Update the Tencent FaceDetection-DSFD installation to include the fix provided in commit a941d089d8ae2df5292a904e79d88649cb58a440.
Proactive Monitoring: Monitor system logs for unexpected process execution or abnormal activity originating from the resnet endpoint.
Compensating Controls: Implement strict input validation or sanitization at the network perimeter to block malicious payloads from reaching the vulnerable endpoint.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
The severity of this vulnerability, combined with the potential for root-level access, requires immediate remediation. Organizations utilizing the affected version of Tencent FaceDetection-DSFD should apply the available upstream fix as soon as possible to prevent potential exploitation of the deserialization flaw.
More Tencent CVEs
Sources
- ZDI-25-1183
- vendor-provided URL Vendor advisory