PT-2026-23461 · Unknown · Rustdesk Server Pro
Erez Kalman
·
Published
2026-03-05
·
Updated
2026-03-05
·
CVE-2026-30796
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RustDesk Server Pro versions through 1.7.5
Description
A security issue exists in RustDesk Server Pro related to the transmission of sensitive information in cleartext. The vulnerability is present in the address book sync API modules and allows for potential sniffing attacks. Specifically, the Heartbeat API handler (
heartbeatApiHandler()) accepts the preset-address-book-password parameter in plaintext, exposing it during transmission. This affects the heartbeat sync functionality.Recommendations
Versions prior to 1.7.6 should be updated.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rustdesk Server Pro