Alongside weak configuration, the products themselves have shipped vulnerabilities that bypass their authentication or execute code, independent of how strong the password is. These are version-specific, so the method is to fingerprint the product and build and match it to the advisory. The notable ones cluster in TeamViewer (authentication/permission flaws and client code-execution issues) and AnyDesk (authentication-bypass and client vulnerabilities), with similar classes across the other products.
Subtopics#
- TeamViewer: authentication bypass and remote code execution.
- AnyDesk auth bypass: bypassing AnyDesk authentication.