CVE-2025-27916

An issue was discovered in AnyDesk through 9.0.4. When the connection between two clients is established via an IP address, it is possible to manipulate the data and spoof the AnyDesk ID.
Configurations

Configuration 1 (hide)

cpe:2.3:a:anydesk:anydesk:*:*:*:*:*:windows:*:*

History

07 Nov 2025, 18:07

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Anydesk anydesk
Anydesk
CPE cpe:2.3:a:anydesk:anydesk:*:*:*:*:*:windows:*:*
References () https://anydesk.com/en/changelog/windows - () https://anydesk.com/en/changelog/windows - Release Notes
References () https://dspace.cvut.cz/bitstream/handle/10467/122721/F8-DP-2025-Krejsa-Vojtech-DP_Krejsa_Vojtech_2025.pdf - () https://dspace.cvut.cz/bitstream/handle/10467/122721/F8-DP-2025-Krejsa-Vojtech-DP_Krejsa_Vojtech_2025.pdf - Exploit, Third Party Advisory
CWE CWE-290

06 Nov 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-06 18:15

Updated : 2025-11-10 20:15


NVD link : CVE-2025-27916

Mitre link : CVE-2025-27916

CVE.ORG link : CVE-2025-27916


JSON object : View

Products Affected

anydesk

  • anydesk
CWE
CWE-290

Authentication Bypass by Spoofing