PT-2025-52849 · Tencent · Tencent Facedetection-Dsfd

Gothburz

+1

·

Published

2025-12-23

·

Updated

2025-12-24

·

CVE-2025-13715

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tencent FaceDetection-DSFD (affected versions not specified)
Description A flaw exists in Tencent FaceDetection-DSFD that allows remote attackers to execute arbitrary code. User interaction is required, such as visiting a malicious page or opening a malicious file. The issue stems from insufficient validation of user-supplied data, leading to deserialization of untrusted data within the resnet endpoint. Successful exploitation could allow an attacker to execute code with root privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-13715
ZDI-25-1183

Affected Products

Tencent Facedetection-Dsfd