CVE-2025-27916

A

n issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before 8.0.0. When the connection between two clients is established via an IP address, it is possible to manipulate the data and spoof the AnyDesk ID.

Configurations

Configuration 1 (hide)

cpe:2.3:a:anydesk:anydesk:*:*:*:*:*:windows:*:*

History

08 Dec 2025, 17:16

Type Values Removed Values Added
Summary (en) An issue was discovered in AnyDesk through 9.0.4. When the connection between two clients is established via an IP address, it is possible to manipulate the data and spoof the AnyDesk ID. (en) An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before 8.0.0. When the connection between two clients is established via an IP address, it is possible to manipulate the data and spoof the AnyDesk ID.

07 Nov 2025, 18:07

Type Values Removed Values Added
First Time Anydesk
Anydesk anydesk
References () https://anydesk.com/en/changelog/windows - () https://anydesk.com/en/changelog/windows - Release Notes
References () https://dspace.cvut.cz/bitstream/handle/10467/122721/F8-DP-2025-Krejsa-Vojtech-DP_Krejsa_Vojtech_2025.pdf - () https://dspace.cvut.cz/bitstream/handle/10467/122721/F8-DP-2025-Krejsa-Vojtech-DP_Krejsa_Vojtech_2025.pdf - Exploit, Third Party Advisory
CPE cpe:2.3:a:anydesk:anydesk:*:*:*:*:*:windows:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-290

06 Nov 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-06 18:15

Updated : 2025-12-08 17:16


NVD link : CVE-2025-27916

Mitre link : CVE-2025-27916

CVE.ORG link : CVE-2025-27916


JSON object : View

Products Affected
CWE
CWE-290

Authentication Bypass by Spoofing