Executive brief
RustDesk, a remote desktop application, contains a security flaw where it transmits address book passwords in an insecure format. If an attacker manages to intercept the connection or trick the software into connecting to a malicious server, they can capture these passwords. This allows the attacker to gain unauthorized access to the user's saved address book and the contact information within it.
Technical details
The RustDesk Client (specifically in src/hbbs_http/sync.rs) transmits the preset address-book password verbatim within the JSON body of heartbeat synchronization requests. While typically protected by HTTPS, the application is vulnerable to a TLS downgrade attack (CVE-2026-30794) or infrastructure hijacking (CVE-2026-30797) that allows a rogue API endpoint to recover the credential. Because the password is a reusable shared secret rather than a zero-knowledge proof (like SRP), an attacker who captures the plaintext can use it to authorize access to the server-side address book. This affects all native clients (Windows, MacOS, Linux, iOS, Android) through version 1.4.8.
Affected products
- RustDesk RustDesk Client through 1.4.8
- RustDesk RustDesk Server Pro through 1.7.5
Timeline
- 2026-03-05: disclosed: Initial vulnerability discovery and publication.
- 2026-06-22: advisory: Advisory updated with expanded version ranges and CWE-522.