PT-2026-23460 · Unknown · Rustdesk Client
Erez Kalman
·
Published
2026-03-05
·
Updated
2026-03-05
·
CVE-2026-30795
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RustDesk Client versions through 1.4.5
Description
A cleartext transmission of sensitive information issue exists in RustDesk Client on Windows, MacOS, Linux, iOS, and Android, specifically within the Heartbeat sync loop modules. This allows for potential sniffing attacks. The issue is related to the construction of Heartbeat JSON payloads, including preset address book passwords, within the
src/hbbs http/sync.Rs file and the Heartbeat routine.Recommendations
Update RustDesk Client to a version later than 1.4.5.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rustdesk Client