PT-2026-5258 · Teamviewer+1 · Teamviewer Dex+1
Published
2026-01-29
·
Updated
2026-02-11
·
CVE-2026-23571
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TeamViewer DEX (former 1E DEX) versions prior to 24.5
Description
A command injection issue exists in TeamViewer DEX (formerly 1E DEX) related to the 1E-Nomad-RunPkgStatusRequest instruction. Insufficient input validation allows attackers with actioner privileges to execute arbitrary commands with elevated permissions on connected hosts by injecting malicious commands into the input field of the instruction.
Recommendations
Update to version 24.5 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
1E Dex
Teamviewer Dex