CVE-2025-64992: Command Injection in 1E-Nomad-PauseNomadJobQueue Instruction
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-PauseNomadJobQueue instruction prior V25. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64992?
CVE-2025-64992 is classified as a critical command injection vulnerability.
How do I fix CVE-2025-64992?
To mitigate CVE-2025-64992, update TeamViewer DEX to version 25 or later.
What software versions are affected by CVE-2025-64992?
CVE-2025-64992 affects all versions of TeamViewer DEX prior to version 25.
Who can exploit CVE-2025-64992?
Authenticated attackers with Actioner privileges can exploit CVE-2025-64992.
What type of vulnerability is CVE-2025-64992?
CVE-2025-64992 is a command injection vulnerability due to improper input validation.