Remote Code Execution Vulnerability in Tencent MedicalNet Software
CVE-2025-13714

7.8HIGH

Key Information:

Vendor

Tencent

Vendor
CVE Published:
23 December 2025

What is CVE-2025-13714?

A vulnerability exists within Tencent MedicalNet's generate_model function, allowing remote attackers to execute arbitrary code due to inadequate validation of user-supplied data. By convincing a user to visit a malicious webpage or open a compromised file, an attacker can exploit this flaw to perform actions with elevated privileges, potentially impacting the entire system. This significant risk underscores the importance of strict input validation and safe coding practices.

Affected Version(s)

MedicalNet 18c8bb6cd564eb1b964bffef1f4c2283f1ae6e7b

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-13714 : Remote Code Execution Vulnerability in Tencent MedicalNet Software