CVE-2025-64989: Command Injection in 1E-Explorer-TachyonCore-FindFileBySizeAndHash Instruction
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-FindFileBySizeAndHash instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64989?
CVE-2025-64989 has been classified as a critical severity vulnerability due to its potential to allow command injection by authenticated attackers.
How do I fix CVE-2025-64989?
To fix CVE-2025-64989, upgrade TeamViewer DEX to version 21.1 or later, which addresses the command injection vulnerability.
Who is affected by CVE-2025-64989?
CVE-2025-64989 affects TeamViewer DEX versions prior to 21.1 that allow users with Actioner privileges to exploit the command injection vulnerability.
What impact does CVE-2025-64989 have on users?
The impact of CVE-2025-64989 includes potential unauthorized execution of commands in the context of affected systems by authenticated attackers.
Is there a workaround for CVE-2025-64989?
Currently, the primary solution for CVE-2025-64989 is to upgrade to the latest version of TeamViewer DEX, as no specific workarounds are recommended.