{"id":"CVE-2025-64986","title":"A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-DevicesListeningOnAPort instruction prior V21","summary":"A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-DevicesListeningOnAPort instruction prior V21. Improper input validation, allowing authenticated attacker…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-20","CWE-77"],"vendor":"teamviewer","product":"digital_employee_experience","affected":["digital_employee_experience < 21.0"],"patched":["digital_employee_experience 21.0"],"published":"2025-12-11","updated":"2026-10-08","sourceUpdated":"2026-10-08T10:10:00.227","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-64986","references":[{"url":"https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2025-1006/","label":"psirt@teamviewer.com"}],"tags":["nvd"],"epss":0.01189,"epssPercentile":0.66985,"ingestedAt":"2026-10-08T10:28:24.726Z","slug":"CVE-2025-64986","body":"## Overview\n\nA command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-DevicesListeningOnAPort instruction prior V21. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.\n\n## Affected\n\n- `digital_employee_experience < 21.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `digital_employee_experience 21.0`","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}