PT-2026-23463 · Unknown · Rustdesk Client
Erez Kalman
·
Published
2026-03-05
·
Updated
2026-03-10
·
CVE-2026-30798
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RustDesk Client versions through 1.4.5
Description
A flaw exists in RustDesk Client related to insufficient verification of data authenticity and improper handling of exceptional conditions, specifically allowing protocol manipulation. The issue resides within the heartbeat sync loop and strategy processing modules, impacting program files
src/hbbs http/sync.Rs and the stop-service handler routine in the heartbeat loop. This allows for the acceptance of unauthenticated stop-service commands via a strategy payload.Recommendations
Update RustDesk Client to a version later than 1.4.5.
Exploit
Fix
Improper Handling of Exceptional Conditions
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rustdesk Client