CVE-2025-3162
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Apr 3, 2025
Updated: Apr 23, 2025
CWE ID 79
Summary
CVE-2025-3162 is a critical vulnerability affecting InternLM LMDeploy version 0.7.1. The issue lies in the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py within the PT File Handler component. An attacker can exploit this deserialization vulnerability by manipulating data locally, making it a requirement for an attack to be successful. The exploit for this vulnerability has been made public, posing a significant risk to affected systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Support Helpdesk Ticket System Lite Plugin
Affected Vendors
- WordPress