CVE-2025-64986
7.2TeamViewer · TeamViewer DEX
A command injection vulnerability in TeamViewer DEX allows authenticated attackers with Actioner privileges to execute arbitrary commands on connected devices via improper input validation.
Executive summary
A command injection vulnerability in TeamViewer DEX poses a high risk, as it allows authenticated attackers with elevated privileges to execute arbitrary commands on affected endpoints.
Vulnerability
This flaw involves improper input validation within the 1E-Explorer-TachyonCore-DevicesListeningOnAPort instruction. It requires the attacker to hold Actioner privileges to successfully inject and execute commands.
Business impact
Successful exploitation of this vulnerability leads to the remote execution of elevated commands on devices connected to the platform. Given the CVSS score of 7.2, this represents a significant risk to system integrity and confidentiality, potentially allowing attackers to compromise the entire device fleet managed through the affected DEX instance.
Remediation
Immediate Action: On-premise users must update to version 21 or later immediately, while SaaS instances have already received automatic updates.
Proactive Monitoring: Security teams should monitor system logs for unusual command execution patterns or unauthorized use of the TachyonCore instruction set.
Compensating Controls: Restrict access to the DEX management console to only essential personnel and ensure that only trusted users are granted the Actioner privilege level.
Exploitation status
Public Exploit Available: exploit_available (unknown)
Analyst recommendation
The vulnerability presents a clear risk to operational security through potential unauthorized command execution. Organizations running on-premise instances of TeamViewer DEX must prioritize the update to version 21 or later to eliminate the command injection vector. Failure to patch may grant malicious actors with existing low-level access the ability to escalate their control over the entire managed device environment.
More TeamViewer CVEs
Sources
Originally found and disclosed by Lockheed Martin Red Team, per the CVE Program record.