A command injection vulnerability was discovered in...
High severity
Unreviewed
Published
Dec 11, 2025
to the GitHub Advisory Database
•
Updated Jan 14, 2026
Description
Published by the National Vulnerability Database
Dec 11, 2025
Published to the GitHub Advisory Database
Dec 11, 2025
Last updated
Jan 14, 2026
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.
References