TeamViewer DEX Command Injection Vulnerability in 1E-Nomad-PauseNomadJobQueue Instruction
Vulnerability
A command injection vulnerability exists in TeamViewer DEX (formerly 1E DEX) versions prior to 25.12. The issue arises within the 1E-Nomad-PauseNomadJobQueue instruction, where improper input validation allows authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation of this vulnerability enables remote execution of elevated commands on devices connected to the platform.
Impact
Successful exploitation allows for command injection, with the injected commands executed remotely on the affected device with elevated privileges.
Remediation
Users can update to TeamViewer DEX version 25.12 or later. For on-premise installations, contact the responsible Customer Success Manager for updates.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
