CVE-2025-3162

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 3, 2025
Updated: Apr 23, 2025
CWE ID 79

Summary

CVE-2025-3162 is a critical vulnerability affecting InternLM LMDeploy version 0.7.1. The issue lies in the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py within the PT File Handler component. An attacker can exploit this deserialization vulnerability by manipulating data locally, making it a requirement for an attack to be successful. The exploit for this vulnerability has been made public, posing a significant risk to affected systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Support Helpdesk Ticket System Lite Plugin

Affected Vendors

  • WordPress