{"id":"CVE-2025-64990","title":"A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instruction prior V21.1","summary":"A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instruction prior V21.1. Improper input validation, allowing authenticated attackers with Acti…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-20"],"vendor":"teamviewer","product":"digital_employee_experience","affected":["digital_employee_experience < 21.1"],"patched":["digital_employee_experience 21.1"],"published":"2025-12-11","updated":"2026-10-08","sourceUpdated":"2026-10-08T10:10:00.227","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-64990","references":[{"url":"https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2025-1006/","label":"psirt@teamviewer.com"}],"tags":["nvd"],"epss":0.00828,"epssPercentile":0.56162,"ingestedAt":"2026-10-08T10:28:24.784Z","slug":"CVE-2025-64990","body":"## Overview\n\nA command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.\n\n## Affected\n\n- `digital_employee_experience < 21.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `digital_employee_experience 21.1`","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":37.4,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}