CVE-2025-46266 MEDIUM

CVE-2025-46266: Unauthenticated Transmission of Data in NomadBranch.exe

Vendor Teamviewer
Product DEX
Weakness CWE-20 · Input validation
Published December 11, 2025
Last update December 11, 2025

CVSS base score

4.3/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to coerce the service into transmitting data to an arbitrary internal IP address, potentially leaking sensitive information.

Key dates

02Disclosure timeline

December 11, 2025 CVE published
December 11, 2025 Record updated