Remote Code Execution Vulnerability in Tencent HunyuanVideo Software
CVE-2025-13710

7.8HIGH

Key Information:

Vendor

Tencent

Vendor
CVE Published:
23 December 2025

What is CVE-2025-13710?

The Tencent HunyuanVideo software contains a vulnerability in the load_vae function, which fails to validate user-supplied data adequately. This flaw allows remote attackers to execute arbitrary code on affected installations by persuading users to access malicious pages or open compromised files. Once exploited, the attacker can execute code with root privileges, posing significant risks to sensitive data and system integrity.

Affected Version(s)

HunyuanVideo Current

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-13710 : Remote Code Execution Vulnerability in Tencent HunyuanVideo Software