PT-2025-50597 · Teamviewer+1 · Teamviewer Dex+1

Published

2025-12-11

·

Updated

2025-12-11

·

CVE-2025-64990

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TeamViewer DEX (former 1E DEX) versions prior to 21.1
Description A command injection issue exists in TeamViewer DEX (formerly 1E DEX) due to improper input validation. This affects the 1E-Explorer-TachyonCore-LogoffUser instruction. An authenticated attacker with Actioner privileges can inject arbitrary commands, leading to remote execution of elevated commands on connected devices.
Recommendations Update TeamViewer DEX to version 21.1 or later.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-64990

Affected Products

1E Dex
Teamviewer Dex