TeamViewer DEX Command Injection Vulnerability in 1E-PatchInsights-Deploy Instruction

Vulnerability

A command injection vulnerability exists in TeamViewer DEX (formerly 1E DEX) within the 1E-PatchInsights-Deploy instruction, prior to version 15. The vulnerability arises from improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation of this vulnerability enables remote execution of elevated commands on devices connected to the platform.

Impact

Exploitation allows for remote execution of elevated commands on affected devices.

Remediation

Users can update to TeamViewer DEX version 25.12 or later. For on-premise installations, contact the responsible Customer Success Manager for updates.

Added: Dec 11, 2025, 12:20 PM
Updated: Dec 11, 2025, 12:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.2
remediation
0.0
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.