AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.
https://github.com/LINCOLINO/lab-annie
https://github.com/Tarimaow/Anydesk-Exploit-CVE-2025-12654-RCE-Builder
https://github.com/Maitonnx/Anydesk-Exploit-CVE-2025-12654-RCE-Builder
https://github.com/Kastowm/Anydesk-Exploit-CVE-2025-12654-RCE-Builder
https://github.com/Taowmz/Anydesk-Exploit-CVE-2025-12654-RCE-Builder
https://github.com/Quelvara/Anydesk-Exploit-CVE-2025-12654-RCE-Builder
https://github.com/Taonauz/Anydesk-Exploit-CVE-2025-12654-RCE-Builder
https://github.com/Yuweixn/Anydesk-Exploit-CVE-2025-12654-RCE-Builder
https://github.com/ThoristKaw/Anydesk-Exploit-CVE-2025-12654-RCE-Builder
https://download.anydesk.com/changelog.txt
https://devel0pment.de/?p=1881
http://packetstormsecurity.com/files/161628/AnyDesk-5.5.2-Remote-Code-Execution.html
http://packetstormsecurity.com/files/158291/AnyDesk-GUI-Format-String-Write.html