CVE-2025-64989 Details
Description
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-FindFileBySizeAndHash instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.
A command injection vulnerability has been identified in TeamViewer DEX (formerly 1E DEX) versions prior to 21.1. This vulnerability resides within the '1E-Explorer-TachyonCore-FindFileBySizeAndHash' instruction. The issue stems from improper input validation, which allows authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation of this vulnerability enables the remote execution of elevated commands on devices connected to the platform.
Users can update to TeamViewer DEX version 21.1 or later. For on-premise customers, instructions should be updated through their responsible Customer Success Manager.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2025-1006/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| teamviewer digital employee experience | < 21.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 14, 2026 | Initial Analysis | [email protected] |
| Dec 11, 2025 | New CVE Received | [email protected] |