PT-2026-5258 · Teamviewer+1 · Teamviewer Dex+1
CVE-2026-23571
·
Publicado
2026-01-29
·
Atualizado
2026-02-11
CVSS v3.1
6.8
Média
| Vetor | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TeamViewer DEX (former 1E DEX) versions prior to 24.5
Description
A command injection issue exists in TeamViewer DEX (formerly 1E DEX) related to the 1E-Nomad-RunPkgStatusRequest instruction. Insufficient input validation allows attackers with actioner privileges to execute arbitrary commands with elevated permissions on connected hosts by injecting malicious commands into the input field of the instruction.
Recommendations
Update to version 24.5 or later.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
1E Dex
Teamviewer Dex