Executive brief
A vulnerability in the RustDesk remote desktop client and server allows attackers to intercept and crack user passwords. When connecting to a Pro server, the software transmits login proofs using weak encryption that can be easily broken if the connection is intercepted. This could allow an unauthorized person to gain full remote access to managed computers, potentially leading to data theft or complete system takeover.
Technical details
The RustDesk Client (through 1.4.8) and Server (Pro through 1.7.5, OSS through 1.1.15) utilize an insecure authentication handshake for API logins. The login proof is constructed using a fast double SHA256 hash over a server-provided salt and challenge, lacking a slow Key Derivation Function (KDF) like Argon2 or bcrypt, which makes it susceptible to offline brute-force attacks. Furthermore, while the peer-to-peer channel is secured, the API login path relies solely on TLS; combined with a separate vulnerability (CVE-2026-30794) that allows automatic downgrades to invalid certificates, an attacker can perform a Man-in-the-Middle (MitM) attack to capture the weak hashes. Successful exploitation allows an attacker to recover the plaintext password and authenticate as the user.
Affected products
- RustDesk RustDesk Client through 1.4.8
- RustDesk RustDesk Server Pro through 1.7.5
- RustDesk RustDesk Server (OSS) through 1.1.15
Timeline
- 2026-03-05: disclosed: Initial discovery and publication of findings by VULSec Labs.
- 2026-03-05: advisory: CVE-2026-30790 assigned and published.
- 2026-06-22: other: Advisory updated with expanded technical details and affected version ranges.