CVE-2025-64987: Command Injection in 1E-Explorer-TachyonCore-CheckSimpleIoC Instruction
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64987?
CVE-2025-64987 has been rated as a high severity vulnerability due to its potential for command injection by authenticated attackers.
How do I fix CVE-2025-64987?
To fix CVE-2025-64987, update your TeamViewer DEX software to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-64987?
CVE-2025-64987 affects users of TeamViewer DEX with Actioner privileges that allow for command execution.
What kind of attacks can occur due to CVE-2025-64987?
Exploitation of CVE-2025-64987 can lead to arbitrary command execution on affected systems.
Is CVE-2025-64987 being actively exploited?
While there are no reports of active exploitation, the nature of CVE-2025-64987 makes it a notable risk that should be addressed promptly.