An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before 8.0.0. When the connection between two clients is established via an IP address, it is possible to manipulate the data and spoof the AnyDesk ID.
References
| Link | Resource |
|---|---|
| https://anydesk.com/en/changelog/windows | Release Notes |
| https://dspace.cvut.cz/bitstream/handle/10467/122721/F8-DP-2025-Krejsa-Vojtech-DP_Krejsa_Vojtech_2025.pdf | Exploit Third Party Advisory |
Configurations
History
08 Dec 2025, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before 8.0.0. When the connection between two clients is established via an IP address, it is possible to manipulate the data and spoof the AnyDesk ID. |
07 Nov 2025, 18:07
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| First Time |
Anydesk anydesk
Anydesk |
|
| CPE | cpe:2.3:a:anydesk:anydesk:*:*:*:*:*:windows:*:* | |
| References | () https://anydesk.com/en/changelog/windows - Release Notes | |
| References | () https://dspace.cvut.cz/bitstream/handle/10467/122721/F8-DP-2025-Krejsa-Vojtech-DP_Krejsa_Vojtech_2025.pdf - Exploit, Third Party Advisory | |
| CWE | CWE-290 |
06 Nov 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-06 18:15
Updated : 2025-12-08 17:16
NVD link : CVE-2025-27916
Mitre link : CVE-2025-27916
CVE.ORG link : CVE-2025-27916
JSON object : View
Products Affected
anydesk
- anydesk
CWE
CWE-290
Authentication Bypass by Spoofing
