Junglewise Threat Intelligence

CVE-2026-30792: RustDesk Client Remote Strategy Injection via Man-in-the-Middle

CVE-2026-30792 · Severity: high · CVSS 8.1 · Published 2026-03-05

Technologies: Rustdesk, Apple macOS, Microsoft Windows, Google Android, RustDesk Client, Apple Iphone Os, Linux Kernel. Vendors: Rustdesk, Apple, Microsoft, Google, Linux.

Executive brief

RustDesk Client, a remote desktop application, contains a vulnerability that allows an attacker to intercept and manipulate communications between the client and its management server. By performing a man-in-the-middle attack, a malicious actor can override local security policies, such as IP whitelists and access permissions, effectively gaining unauthorized control over the remote device. This could lead to unauthorized access to sensitive systems, data exposure, or the disabling of security features across an organization's fleet of devices.

Technical details

A vulnerability in the Strategy sync and HTTP API client modules of RustDesk Client allows for Application API Message Manipulation via Man-in-the-Middle. The root cause is located in `src/hbbs_http/sync.rs` (strategy merge loop) and `hbb_common/src/config.rs` (`Config::set_options()`), where the client blindly merges strategy configurations from the server without sufficient verification of data authenticity (CWE-345). Because the client follows a settings hierarchy where 'Strategy' overrides 'User' settings, an attacker capable of intercepting the connection (facilitated by a TLS fallback flaw in `http_client.rs`) can inject malicious payloads to clear IP whitelists, escalate access modes from view-only to full-control, or re-enable disabled features like file transfers. This affects clients on Windows, MacOS, Linux, iOS, Android, and WebClient through version 1.4.8.

Affected products

  • RustDesk RustDesk Client through 1.4.8

Timeline

  • 2026-03-05: disclosed: Initial discovery and publication of findings
  • 2026-06-22: advisory: Updated advisory confirming vulnerability persists in version 1.4.8

References

Related threats